Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.os.linux.misc > #70357 > unrolled thread
| Started by | Lawrence D'Oliveiro <ldo@nz.invalid> |
|---|---|
| First post | 2025-08-05 08:14 +0000 |
| Last post | 2025-08-23 05:43 +0000 |
| Articles | 20 on this page of 113 — 24 participants |
Back to article view | Back to comp.os.linux.misc
Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D'Oliveiro <ldo@nz.invalid> - 2025-08-05 08:14 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Marc Haber <mh+usenetspam1118@zugschl.us> - 2025-08-05 11:22 +0200
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Marco Moock <mm@dorfdsl.de> - 2025-08-05 11:34 +0200
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use jayjwa <jayjwa@atr2.ath.cx.invalid> - 2025-08-05 11:30 -0400
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use The Natural Philosopher <tnp@invalid.invalid> - 2025-08-05 19:56 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D'Oliveiro <ldo@nz.invalid> - 2025-08-06 01:06 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use John McCue <jmclnx@gmail.com.invalid> - 2025-08-06 01:32 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D'Oliveiro <ldo@nz.invalid> - 2025-08-06 04:20 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use c186282 <c186282@nnada.net> - 2025-08-06 01:33 -0400
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Mike Scott <usenet.16@scottsonline.org.uk.invalid> - 2025-08-06 09:31 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D'Oliveiro <ldo@nz.invalid> - 2025-08-06 08:56 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Nuno Silva <nunojsilva@invalid.invalid> - 2025-08-06 10:35 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Mike Scott <usenet.16@scottsonline.org.uk.invalid> - 2025-08-06 11:38 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D'Oliveiro <ldo@nz.invalid> - 2025-08-07 00:06 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Mike Scott <usenet.16@scottsonline.org.uk.invalid> - 2025-08-11 11:50 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D'Oliveiro <ldo@nz.invalid> - 2025-08-11 22:02 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Mike Scott <usenet.16@scottsonline.org.uk.invalid> - 2025-08-12 08:39 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Marc Haber <mh+usenetspam1118@zugschl.us> - 2025-08-12 10:49 +0200
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use The Natural Philosopher <tnp@invalid.invalid> - 2025-08-12 10:54 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Charlie Gibbs <cgibbs@kltpzyxm.invalid> - 2025-08-12 18:47 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D'Oliveiro <ldo@nz.invalid> - 2025-08-12 23:36 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use "Carlos E. R." <robin_listas@es.invalid> - 2025-08-12 12:08 +0200
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use rbowman <bowman@montana.com> - 2025-08-12 19:35 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D'Oliveiro <ldo@nz.invalid> - 2025-08-12 23:07 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Mike Scott <usenet.16@scottsonline.org.uk.invalid> - 2025-08-13 09:47 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D'Oliveiro <ldo@nz.invalid> - 2025-08-14 00:41 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use "Carlos E.R." <robin_listas@es.invalid> - 2025-08-19 12:35 +0200
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Mike Scott <usenet.16@scottsonline.org.uk.invalid> - 2025-08-19 12:18 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Marc Haber <mh+usenetspam1118@zugschl.us> - 2025-08-19 15:16 +0200
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-20 01:02 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Mike Scott <usenet.16@scottsonline.org.uk.invalid> - 2025-08-27 06:56 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-28 00:50 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Mike Scott <usenet.16@scottsonline.org.uk.invalid> - 2025-08-28 09:40 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-29 00:56 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use John Ames <commodorejohn@gmail.com> - 2025-08-29 08:10 -0700
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Mike Scott <usenet.16@scottsonline.org.uk.invalid> - 2025-08-29 19:16 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Tauno Voipio <tauno.voipio@notused.fi.invalid> - 2025-08-30 16:59 +0300
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Mike Scott <usenet.16@scottsonline.org.uk.invalid> - 2025-08-30 18:45 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Tauno Voipio <tauno.voipio@notused.fi.invalid> - 2025-08-31 21:24 +0300
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Mike Scott <usenet.16@scottsonline.org.uk.invalid> - 2025-09-01 17:02 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-31 03:25 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-30 06:34 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Nuno Silva <nunojsilva@invalid.invalid> - 2025-08-30 08:39 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use The Natural Philosopher <tnp@invalid.invalid> - 2025-08-30 08:45 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Harold Stevens <wookie@trixie.localdomain> - 2025-08-30 05:37 -0500
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use John Ames <commodorejohn@gmail.com> - 2025-09-02 09:59 -0700
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Harold Stevens <wookie@aspen.localdomain> - 2025-09-02 12:59 -0500
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Richard Kettlewell <invalid@invalid.invalid> - 2025-08-30 17:48 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-20 01:01 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use "Carlos E.R." <robin_listas@es.invalid> - 2025-08-20 12:52 +0200
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-20 22:36 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use "Carlos E.R." <robin_listas@es.invalid> - 2025-08-21 11:44 +0200
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use The Natural Philosopher <tnp@invalid.invalid> - 2025-08-21 11:34 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use "Carlos E.R." <robin_listas@es.invalid> - 2025-08-21 14:36 +0200
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Nuno Silva <nunojsilva@invalid.invalid> - 2025-08-21 14:27 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use "Carlos E.R." <robin_listas@es.invalid> - 2025-08-21 21:37 +0200
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Nuno Silva <nunojsilva@invalid.invalid> - 2025-08-22 10:33 +0100
Manuals [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] "Carlos E.R." <robin_listas@es.invalid> - 2025-08-22 12:39 +0200
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-22 01:12 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-22 01:06 +0000
Documentation [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] "Carlos E.R." <robin_listas@es.invalid> - 2025-08-22 12:26 +0200
Re: Documentation [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-23 23:13 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use John Ames <commodorejohn@gmail.com> - 2025-08-20 07:47 -0700
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-20 22:37 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Stéphane CARPENTIER <sc@fiat-linux.fr> - 2025-08-20 19:25 +0000
tldr [WAS: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] "Carlos E.R." <robin_listas@es.invalid> - 2025-08-21 12:04 +0200
Re: tldr [WAS: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] Stéphane CARPENTIER <sc@fiat-linux.fr> - 2025-08-23 12:40 +0000
Re: tldr [WAS: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] "Carlos E.R." <robin_listas@es.invalid> - 2025-08-24 00:40 +0200
Re: tldr [WAS: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-23 23:15 +0000
Re: tldr [WAS: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] Stéphane CARPENTIER <sc@fiat-linux.fr> - 2025-08-24 11:22 +0000
Re: tldr [WAS: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-24 22:18 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Anssi Saari <anssi.saari@usenet.mail.kapsi.fi> - 2025-08-21 12:40 +0300
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Richard Kettlewell <invalid@invalid.invalid> - 2025-08-06 14:21 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use The Natural Philosopher <tnp@invalid.invalid> - 2025-08-06 16:24 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use The Natural Philosopher <tnp@invalid.invalid> - 2025-08-06 10:12 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Anssi Saari <anssi.saari@usenet.mail.kapsi.fi> - 2025-08-07 11:43 +0300
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use John McCue <jmclnx@gmail.com.invalid> - 2025-08-06 11:55 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Marc Haber <mh+usenetspam1118@zugschl.us> - 2025-08-06 07:40 +0200
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D'Oliveiro <ldo@nz.invalid> - 2025-08-06 06:31 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Marc Haber <mh+usenetspam1118@zugschl.us> - 2025-08-06 11:06 +0200
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Richard Kettlewell <invalid@invalid.invalid> - 2025-08-06 14:25 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Marc Haber <mh+usenetspam1118@zugschl.us> - 2025-08-06 17:11 +0200
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D'Oliveiro <ldo@nz.invalid> - 2025-08-06 23:59 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Marc Haber <mh+usenetspam1118@zugschl.us> - 2025-08-07 08:37 +0200
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D'Oliveiro <ldo@nz.invalid> - 2025-08-07 06:52 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Rich <rich@example.invalid> - 2025-08-18 16:49 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use "Carlos E.R." <robin_listas@es.invalid> - 2025-08-06 12:46 +0200
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D'Oliveiro <ldo@nz.invalid> - 2025-08-06 23:56 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use "Carlos E.R." <robin_listas@es.invalid> - 2025-08-19 12:41 +0200
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-20 01:07 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Nuno Silva <nunojsilva@invalid.invalid> - 2025-08-20 09:48 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use The Natural Philosopher <tnp@invalid.invalid> - 2025-08-20 11:13 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-20 22:40 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use vallor <vallor@cultnix.org> - 2025-08-21 00:27 +0000
ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] "Carlos E.R." <robin_listas@es.invalid> - 2025-08-20 13:04 +0200
Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] The Natural Philosopher <tnp@invalid.invalid> - 2025-08-20 12:30 +0100
Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-20 22:44 +0000
Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] "Carlos E.R." <robin_listas@es.invalid> - 2025-08-21 12:15 +0200
Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-22 01:18 +0000
Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] "Carlos E.R." <robin_listas@es.invalid> - 2025-08-22 12:45 +0200
Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] The Natural Philosopher <tnp@invalid.invalid> - 2025-08-22 19:37 +0100
Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] "Carlos E.R." <robin_listas@es.invalid> - 2025-08-22 22:32 +0200
Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] The Natural Philosopher <tnp@invalid.invalid> - 2025-08-22 21:56 +0100
Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-23 00:28 +0000
Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] rbowman <bowman@montana.com> - 2025-08-23 05:51 +0000
Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] The Natural Philosopher <tnp@invalid.invalid> - 2025-08-23 11:23 +0100
Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-23 23:12 +0000
Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] candycanearter07 <candycanearter07@candycanearter07.nomail.afraid> - 2025-08-29 19:40 +0000
Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] rbowman <bowman@montana.com> - 2025-08-30 05:59 +0000
Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-30 06:36 +0000
Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] Marc Haber <mh+usenetspam1118@zugschl.us> - 2025-08-30 10:36 +0200
Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-31 01:25 +0000
Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] rbowman <bowman@montana.com> - 2025-08-23 05:43 +0000
Page 5 of 6 — ← Prev page 1 2 3 4 [5] 6 Next page →
| From | Richard Kettlewell <invalid@invalid.invalid> |
|---|---|
| Date | 2025-08-06 14:25 +0100 |
| Message-ID | <wwvjz3g8tv0.fsf@LkoBDZeT.terraraq.uk> |
| In reply to | #70452 |
Marc Haber <mh+usenetspam1118@zugschl.us> writes: > Lawrence D'Oliveiro <ldo@nz.invalid> wrote: >> Marc Haber wrote: >>> Second, blocking incoming echo requests makes debugging harder and >>> doesn't give you increased security. >> >> When a certain server I had responsibility for was undergoing a >> security audit for PCI compliance many years ago, I was told, not to >> turn off ICMP replies, but to turn off timestamps on them. >> >> Apparently, knowing the server’s idea of the correct time was seen as >> a potential security vulnerability. The justification is more likely to have been attack surface minimization. > Those consultants are paid to find things. Hence, they find things. Or > they make things up. The persons who hire them don't care as long as > there is a report. A common approach to security is block or disable everything you don’t need, and leave only the things you do need enabled. -- https://www.greenend.org.uk/rjk/
[toc] | [prev] | [next] | [standalone]
| From | Marc Haber <mh+usenetspam1118@zugschl.us> |
|---|---|
| Date | 2025-08-06 17:11 +0200 |
| Message-ID | <106vrb0$1e3u4$1@news1.tnib.de> |
| In reply to | #70480 |
Richard Kettlewell <invalid@invalid.invalid> wrote: >Marc Haber <mh+usenetspam1118@zugschl.us> writes: >> Those consultants are paid to find things. Hence, they find things. Or >> they make things up. The persons who hire them don't care as long as >> there is a report. > >A common approach to security is block or disable everything you don’t >need, and leave only the things you do need enabled. Then the discussion moves to what is needed. From an operations point of view, I NEED debugging. Greetings Marc -- ---------------------------------------------------------------------------- Marc Haber | " Questions are the | Mailadresse im Header Rhein-Neckar, DE | Beginning of Wisdom " | Nordisch by Nature | Lt. Worf, TNG "Rightful Heir" | Fon: *49 6224 1600402
[toc] | [prev] | [next] | [standalone]
| From | Lawrence D'Oliveiro <ldo@nz.invalid> |
|---|---|
| Date | 2025-08-06 23:59 +0000 |
| Message-ID | <1070q96$3m69k$11@dont-email.me> |
| In reply to | #70487 |
On Wed, 06 Aug 2025 17:11:28 +0200, Marc Haber wrote: > Richard Kettlewell <invalid@invalid.invalid> wrote: >> >>A common approach to security is block or disable everything you don’t >>need, and leave only the things you do need enabled. > > Then the discussion moves to what is needed. From an operations point of > view, I NEED debugging. No reason to make those interfaces public, though. E.g. for one client, we have the production system on the main VM, even though that was originally set up just for me to use for testing. So when I needed an additional test setup, I created an LXC container within the VM, running a separate copy of the software that is not actually directly accessible outside the machine. I can only get to it via an SSH tunnel.
[toc] | [prev] | [next] | [standalone]
| From | Marc Haber <mh+usenetspam1118@zugschl.us> |
|---|---|
| Date | 2025-08-07 08:37 +0200 |
| Message-ID | <1071hk6$1id3o$1@news1.tnib.de> |
| In reply to | #70515 |
Lawrence D'Oliveiro <ldo@nz.invalid> wrote: >On Wed, 06 Aug 2025 17:11:28 +0200, Marc Haber wrote: > >> Richard Kettlewell <invalid@invalid.invalid> wrote: >>> >>>A common approach to security is block or disable everything you don’t >>>need, and leave only the things you do need enabled. >> >> Then the discussion moves to what is needed. From an operations point of >> view, I NEED debugging. > >No reason to make those interfaces public, though. Yes, that's a different point of view. My different point of view is not to take security measures that don't increase security but instead make regular life harder. If a box provides a service to the public, the public already knows it's there, and IP header analysis can also be done by accessing the service the machine is there to provide. Let's agree to disagree here. -- ---------------------------------------------------------------------------- Marc Haber | " Questions are the | Mailadresse im Header Rhein-Neckar, DE | Beginning of Wisdom " | Nordisch by Nature | Lt. Worf, TNG "Rightful Heir" | Fon: *49 6224 1600402
[toc] | [prev] | [next] | [standalone]
| From | Lawrence D'Oliveiro <ldo@nz.invalid> |
|---|---|
| Date | 2025-08-07 06:52 +0000 |
| Message-ID | <1071ifh$3qrld$1@dont-email.me> |
| In reply to | #70527 |
On Thu, 07 Aug 2025 08:37:57 +0200, Marc Haber wrote: > Lawrence D'Oliveiro <ldo@nz.invalid> wrote: >> >> On Wed, 06 Aug 2025 17:11:28 +0200, Marc Haber wrote: >> >>> Then the discussion moves to what is needed. From an operations point >>> of view, I NEED debugging. >> >> No reason to make those interfaces public, though. > > Yes, that's a different point of view. My different point of view is not > to take security measures that don't increase security but instead make > regular life harder. If a box provides a service to the public, the > public already knows it's there, and IP header analysis can also be done > by accessing the service the machine is there to provide. > > Let's agree to disagree here. Too many security holes have been inadvertently left through things like diagnostic ports that should have been closed after testing had completed, but found their way into the shipping product, back-door “testing” accounts with full privileges and hard-coded passwords again that should have been removed from the production code but were not, that kind of thing.
[toc] | [prev] | [next] | [standalone]
| From | Rich <rich@example.invalid> |
|---|---|
| Date | 2025-08-18 16:49 +0000 |
| Message-ID | <107vlj4$36r35$1@dont-email.me> |
| In reply to | #70480 |
Richard Kettlewell <invalid@invalid.invalid> wrote: > Marc Haber <mh+usenetspam1118@zugschl.us> writes: >> Lawrence D'Oliveiro <ldo@nz.invalid> wrote: >>> Marc Haber wrote: >>>> Second, blocking incoming echo requests makes debugging harder and >>>> doesn't give you increased security. >>> >>> When a certain server I had responsibility for was undergoing a >>> security audit for PCI compliance many years ago, I was told, not >>> to turn off ICMP replies, but to turn off timestamps on them. >>> >>> Apparently, knowing the server’s idea of the correct time was seen >>> as a potential security vulnerability. > > The justification is more likely to have been attack surface > minimization. Another possibility is attempting to cover up for an insecure initialization of a random number generator from "the current time".
[toc] | [prev] | [next] | [standalone]
| From | "Carlos E.R." <robin_listas@es.invalid> |
|---|---|
| Date | 2025-08-06 12:46 +0200 |
| Message-ID | <6dobmlx9de.ln2@Telcontar.valinor> |
| In reply to | #70416 |
On 2025-08-06 03:32, John McCue wrote: > jayjwa <jayjwa@atr2.ath.cx.invalid> wrote: >> I say it depends on the situation. For a home user, no. Unless you >> open something there's nothing listening there to exploit. > > Yes and no :) If you are on a Laptop and travel, you may > want a firewall even if all ports are closed. I think > at the very least you should restrict your system from > reacting to pings (see below). FWIW, I always have a > iptables firewall active. > > <snip> I don't trust my router, provided by the ISP. Thus all my computers have a firewall up. -- Cheers, Carlos.
[toc] | [prev] | [next] | [standalone]
| From | Lawrence D'Oliveiro <ldo@nz.invalid> |
|---|---|
| Date | 2025-08-06 23:56 +0000 |
| Message-ID | <1070q3q$3m69k$10@dont-email.me> |
| In reply to | #70463 |
On Wed, 6 Aug 2025 12:46:30 +0200, Carlos E.R. wrote: > I don't trust my router, provided by the ISP. I bought my own. I could even run my own routing stack on a Linux box.
[toc] | [prev] | [next] | [standalone]
| From | "Carlos E.R." <robin_listas@es.invalid> |
|---|---|
| Date | 2025-08-19 12:41 +0200 |
| Message-ID | <a01enlxmr9.ln2@Telcontar.valinor> |
| In reply to | #70514 |
On 2025-08-07 01:56, Lawrence D'Oliveiro wrote: > On Wed, 6 Aug 2025 12:46:30 +0200, Carlos E.R. wrote: > >> I don't trust my router, provided by the ISP. > > I bought my own. I could even run my own routing stack on a Linux box. The configuration needed by the ISP on the router is not documented, you have to reverse engineer the existing documentation in one of their routers. And it is far from simple. The router handles internet, obviously, but also phone and TV. And then, when the router (or anything) stops working, you are on your own. -- Cheers, Carlos.
[toc] | [prev] | [next] | [standalone]
| From | Lawrence D’Oliveiro <ldo@nz.invalid> |
|---|---|
| Date | 2025-08-20 01:07 +0000 |
| Message-ID | <1083746$1m96$13@dont-email.me> |
| In reply to | #71643 |
On Tue, 19 Aug 2025 12:41:46 +0200, Carlos E.R. wrote: > On 2025-08-07 01:56, Lawrence D'Oliveiro wrote: >> >> On Wed, 6 Aug 2025 12:46:30 +0200, Carlos E.R. wrote: >> >>> I don't trust my router, provided by the ISP. >> >> I bought my own. I could even run my own routing stack on a Linux box. > > The configuration needed by the ISP on the router is not documented ... Here in NZ it’s all standard protocols. I bought the router from a local retailer, not from the ISP. Setup was straightforward -- the router calls the setup option I am using “Dynamic IP”, but I think it’s just DHCP.
[toc] | [prev] | [next] | [standalone]
| From | Nuno Silva <nunojsilva@invalid.invalid> |
|---|---|
| Date | 2025-08-20 09:48 +0100 |
| Message-ID | <108425m$7efa$3@dont-email.me> |
| In reply to | #71699 |
On 2025-08-20, Lawrence D’Oliveiro wrote: > On Tue, 19 Aug 2025 12:41:46 +0200, Carlos E.R. wrote: > >> On 2025-08-07 01:56, Lawrence D'Oliveiro wrote: >>> >>> On Wed, 6 Aug 2025 12:46:30 +0200, Carlos E.R. wrote: >>> >>>> I don't trust my router, provided by the ISP. >>> >>> I bought my own. I could even run my own routing stack on a Linux box. >> >> The configuration needed by the ISP on the router is not documented ... > > Here in NZ it’s all standard protocols. I bought the router from a local > retailer, not from the ISP. Setup was straightforward -- the router calls > the setup option I am using “Dynamic IP”, but I think it’s just DHCP. In this case, I think we're talking about a box with router and a bunch of other stuff, to deal with incoming GPON (can this part still be called modem, or the workings of fiber disqualify that?) and at least outgoing coax for TV, RJ11 for telephony and 8p8c for Ethernet. I've seen these called "ONT", but it seems (from another thread here) that this may not be entirely appropriate either? -- Nuno Silva
[toc] | [prev] | [next] | [standalone]
| From | The Natural Philosopher <tnp@invalid.invalid> |
|---|---|
| Date | 2025-08-20 11:13 +0100 |
| Message-ID | <108474l$7mtq$17@dont-email.me> |
| In reply to | #71720 |
On 20/08/2025 09:48, Nuno Silva wrote: > On 2025-08-20, Lawrence D’Oliveiro wrote: > >> On Tue, 19 Aug 2025 12:41:46 +0200, Carlos E.R. wrote: >> >>> On 2025-08-07 01:56, Lawrence D'Oliveiro wrote: >>>> >>>> On Wed, 6 Aug 2025 12:46:30 +0200, Carlos E.R. wrote: >>>> >>>>> I don't trust my router, provided by the ISP. >>>> >>>> I bought my own. I could even run my own routing stack on a Linux box. >>> >>> The configuration needed by the ISP on the router is not documented ... >> >> Here in NZ it’s all standard protocols. I bought the router from a local >> retailer, not from the ISP. Setup was straightforward -- the router calls >> the setup option I am using “Dynamic IP”, but I think it’s just DHCP. > > In this case, I think we're talking about a box with router and a bunch > of other stuff, to deal with incoming GPON (can this part still be > called modem, or the workings of fiber disqualify that?) I call it a modem, because it modulates and demodulates from IP over Ethernet to GPON over fibre, but I get called out because BT call it NTE. Network termination equipment. Which it only is as far as their legal responsibility goes. NTEs are the ethernet chips in my devices, te UK currently and with coax its common to have a separate 'modem' and 'router' Wankers > and at least > outgoing coax for TV, RJ11 for telephony and 8p8c for Ethernet. > > I've seen these called "ONT", but it seems (from another thread here) > that this may not be entirely appropriate either? > Optical Network Terminator. That's better than NTE at least Oh well, its all grist to the ArtStudent™ mill where names and ideas are far more important that the reality of what they refer to. Routers were never juts routers either, they were routers plus switches plus modems plus wireless bridges... -- When plunder becomes a way of life for a group of men in a society, over the course of time they create for themselves a legal system that authorizes it and a moral code that glorifies it. Frédéric Bastiat
[toc] | [prev] | [next] | [standalone]
| From | Lawrence D’Oliveiro <ldo@nz.invalid> |
|---|---|
| Date | 2025-08-20 22:40 +0000 |
| Message-ID | <1085itr$j3am$13@dont-email.me> |
| In reply to | #71740 |
On Wed, 20 Aug 2025 11:13:41 +0100, The Natural Philosopher wrote: > Routers were never juts routers either, they were routers plus switches > plus modems plus wireless bridges... My router has no “modem” functionality (unless you count Ethernet as requiring a “modem”). It has four Ethernet ports, which can be individually configured to be on any of three separate networks, so I’m not sure if that counts as “routing” or “switching”. Its wi-fi functionality is disabled, since that is currently provided by a separate Linux box that is bridging the wi-fi with the Ethernet LAN.
[toc] | [prev] | [next] | [standalone]
| From | vallor <vallor@cultnix.org> |
|---|---|
| Date | 2025-08-21 00:27 +0000 |
| Message-ID | <mgn7flF8ba2U9@mid.individual.net> |
| In reply to | #71740 |
On Wed, 20 Aug 2025 11:13:41 +0100, The Natural Philosopher <tnp@invalid.invalid> wrote in <108474l$7mtq$17@dont-email.me>: > Optical Network Terminator. That's better than NTE at least > > Oh well, its all grist to the ArtStudent™ mill where names and ideas are > far more important that the reality of what they refer to. > > Routers were never juts routers either, they were routers plus switches > plus modems plus wireless bridges... Here I have an ONT -- which acts as a special bridge -- which connects via 10GBaseT to the 10G Eero router, which has 10G ports and wifi. 10G to my 10G switch, which handles my 10G workstation and 10G Synology NAS. I need to run a Cat-7 wire straight down to Mrs. vallor's office downstairs so she'll be wired, but currently, the wifi signal is strong -- and she hasn't complained. I tried setting up Link Aggregation with this Netgear switch (my workstation has 2 - 10GBase-T ports, as does the NAS), but the switch only handles Static LAG, and it's a bit flakey. I bought a switch to replace it that supports LACP, but haven't gotten the round tuit to move over to it yet. Oh, and the connection to the ONT is 10G XPON. We believe in getting customers to go as fast as possible -- this nonsense by our competitors to hold down connection speeds so they can soak the customer for upgrades stinks to high heaven. Finally, the Eero router does IPv4 NAT, and also acts as a firewall for IPv6. Native IPv6 is a lovely thing. -- -v System76 Thelio Mega v1.1 x86_64 NVIDIA RTX 3090Ti 24G OS: Linux 6.16.1 D: Mint 22.1 DE: Xfce 4.18 NVIDIA: 580.76.05 Mem: 258G "Some minds should be cultivated, others plowed under..."
[toc] | [prev] | [next] | [standalone]
| From | "Carlos E.R." <robin_listas@es.invalid> |
|---|---|
| Date | 2025-08-20 13:04 +0200 |
| Subject | ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] |
| Message-ID | <emmgnlxv15.ln2@Telcontar.valinor> |
| In reply to | #71720 |
On 2025-08-20 10:48, Nuno Silva wrote: > On 2025-08-20, Lawrence D’Oliveiro wrote: > >> On Tue, 19 Aug 2025 12:41:46 +0200, Carlos E.R. wrote: >> >>> On 2025-08-07 01:56, Lawrence D'Oliveiro wrote: >>>> >>>> On Wed, 6 Aug 2025 12:46:30 +0200, Carlos E.R. wrote: >>>> >>>>> I don't trust my router, provided by the ISP. >>>> >>>> I bought my own. I could even run my own routing stack on a Linux box. >>> >>> The configuration needed by the ISP on the router is not documented ... >> >> Here in NZ it’s all standard protocols. I bought the router from a local >> retailer, not from the ISP. Setup was straightforward -- the router calls >> the setup option I am using “Dynamic IP”, but I think it’s just DHCP. > > In this case, I think we're talking about a box with router and a bunch > of other stuff, to deal with incoming GPON (can this part still be > called modem, or the workings of fiber disqualify that?) and at least > outgoing coax for TV, RJ11 for telephony and 8p8c for Ethernet. > > I've seen these called "ONT", but it seems (from another thread here) > that this may not be entirely appropriate either? Yes, it is GPON. Now the ONT is integrated inside the router. So the router has an optical input, has two phone connectors, 4 ethernet connectors, and one WiFi access point. It is all standard protocols, but they have to be configured. The optical interface needs some parameters, maybe there is a login and password or client number somewhere. The channel in the GPON setup. The television service needs an VLAN, the VoIp phone service needs another... there are a lot of details in the configuration of those many standard services that have to be configured. There is not, to my knowledge, an ISP provided document listing all that. There might be in the market routers in which I simply click "Telefónica Spain setup" and all is done, but I don't know about them. This did exist with ADSL. -- Cheers, Carlos.
[toc] | [prev] | [next] | [standalone]
| From | The Natural Philosopher <tnp@invalid.invalid> |
|---|---|
| Date | 2025-08-20 12:30 +0100 |
| Subject | Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] |
| Message-ID | <1084bkf$7mtq$25@dont-email.me> |
| In reply to | #71752 |
On 20/08/2025 12:04, Carlos E.R. wrote: > Yes, it is GPON. Now the ONT is integrated inside the router. So the > router has an optical input, has two phone connectors, 4 ethernet > connectors, and one WiFi access point. > Sadly not Over Here it aint ... > It is all standard protocols, but they have to be configured. The > optical interface needs some parameters, maybe there is a login and > password or client number somewhere. The channel in the GPON setup. > The television service needs an VLAN, the VoIp phone service needs > another... there are a lot of details in the configuration of those many > standard services that have to be configured. There is not, to my > knowledge, an ISP provided document listing all that. > > There might be in the market routers in which I simply click "Telefónica > Spain setup" and all is done, but I don't know about them. This did > exist with ADSL. > Yes. insofar as parameters are common across all the carriers installations, this can be done. UK ISDN was just different enough from US to make setting up a Cisco impossible without the right 'magic spell'. Well we stumble on in different ways until one turns out to be 'best' or at least 'adequate cheap enough and what everyone uses' It's a real lesson to apply to Darwin. Never 'survival of the fittest', just elimination of the truly terrible, completely bonkers, marginally worse and just plain unlucky... -- “It is hard to imagine a more stupid decision or more dangerous way of making decisions than by putting those decisions in the hands of people who pay no price for being wrong.” Thomas Sowell
[toc] | [prev] | [next] | [standalone]
| From | Lawrence D’Oliveiro <ldo@nz.invalid> |
|---|---|
| Date | 2025-08-20 22:44 +0000 |
| Subject | Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] |
| Message-ID | <1085j44$j3am$14@dont-email.me> |
| In reply to | #71752 |
On Wed, 20 Aug 2025 13:04:14 +0200, Carlos E.R. wrote: > Yes, it is GPON. Now the ONT is integrated inside the router. Not here in NZ, it isn’t. The demarcation is clear: the ONT is part of the house fittings (like curtains or the oven), while the router is a separate piece of property. The physical fibre network, up to and including the ONT, is managed by a company (Tuatahi Fibre) that is not an ISP and does not provide any Internet services.
[toc] | [prev] | [next] | [standalone]
| From | "Carlos E.R." <robin_listas@es.invalid> |
|---|---|
| Date | 2025-08-21 12:15 +0200 |
| Subject | Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] |
| Message-ID | <m68jnlxg6h.ln2@Telcontar.valinor> |
| In reply to | #71800 |
On 2025-08-21 00:44, Lawrence D’Oliveiro wrote: > On Wed, 20 Aug 2025 13:04:14 +0200, Carlos E.R. wrote: > >> Yes, it is GPON. Now the ONT is integrated inside the router. > > Not here in NZ, it isn’t. The demarcation is clear: the ONT is part of the > house fittings (like curtains or the oven), while the router is a separate > piece of property. The physical fibre network, up to and including the > ONT, is managed by a company (Tuatahi Fibre) that is not an ISP and does > not provide any Internet services. When I had an ONT, it was also supplied by the ISP. The fibre connected to the ONT, and from that it came out an ethernet cable to the router, also supplied by the ISP, and the phone cable. One day they came, removed the ONT and the router, and placed a new router. One box less. Everything belongs to one company, Telefónica. It is possible to contract a different company, but the physical fibre is the same one. There is also another company that has fibre to the block, then coax to the home. -- Cheers, Carlos.
[toc] | [prev] | [next] | [standalone]
| From | Lawrence D’Oliveiro <ldo@nz.invalid> |
|---|---|
| Date | 2025-08-22 01:18 +0000 |
| Subject | Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] |
| Message-ID | <1088gh9$19b27$6@dont-email.me> |
| In reply to | #71838 |
On Thu, 21 Aug 2025 12:15:18 +0200, Carlos E.R. wrote: > One day they came, removed the ONT and the router, and placed a new > router. One box less. And no more possibility of demarcation. Bad. Another thing that the ONT allows is, I have my landline from a different provider from my Internet connection. They come out of different ports on the box in my house, though they get here on the same physical piece of fibre. > Everything belongs to one company, Telefónica. It is possible to > contract a different company, but the physical fibre is the same one. This sounds like NZ about 30 years ago, after NZ Telecom was privatized, and just as the Internet was taking off. Too late, it was realized that this left control of the entire NZ phone-number space, as well as ownership of the copper lines into every household, in private hands. The latter problem was solved by the local-loop unbundling I mentioned elsewhere -- some described it as a renationalization of the “last-mile” copper network in all but name. That made a big difference to the competitiveness of the broadband market. And the mistake was not repeated when the fibre network was put in place.
[toc] | [prev] | [next] | [standalone]
| From | "Carlos E.R." <robin_listas@es.invalid> |
|---|---|
| Date | 2025-08-22 12:45 +0200 |
| Subject | Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] |
| Message-ID | <8bulnlxf5e.ln2@Telcontar.valinor> |
| In reply to | #71892 |
On 2025-08-22 03:18, Lawrence D’Oliveiro wrote: > On Thu, 21 Aug 2025 12:15:18 +0200, Carlos E.R. wrote: > >> One day they came, removed the ONT and the router, and placed a new >> router. One box less. > > And no more possibility of demarcation. Bad. One good thing, is that we have access to the VoIP configuration and install (undocumented) true VoIP phones. We did not have access to configure the ONT, and thus, the phone. I believe people have reverse engineered it all. I was told there is some EU directive saying people have the right to install their own routers. > > Another thing that the ONT allows is, I have my landline from a different > provider from my Internet connection. They come out of different ports on > the box in my house, though they get here on the same physical piece of > fibre. > >> Everything belongs to one company, Telefónica. It is possible to >> contract a different company, but the physical fibre is the same one. > > This sounds like NZ about 30 years ago, after NZ Telecom was privatized, > and just as the Internet was taking off. Too late, it was realized that > this left control of the entire NZ phone-number space, as well as > ownership of the copper lines into every household, in private hands. > > The latter problem was solved by the local-loop unbundling I mentioned > elsewhere -- some described it as a renationalization of the “last-mile” > copper network in all but name. That made a big difference to the > competitiveness of the broadband market. > > And the mistake was not repeated when the fibre network was put in place. I worked in this field years ago, before fibre. I have not seen the fibre exchanges, how they do things. -- Cheers, Carlos.
[toc] | [prev] | [next] | [standalone]
Page 5 of 6 — ← Prev page 1 2 3 4 [5] 6 Next page →
Back to top | Article view | comp.os.linux.misc
csiph-web