Re: [LUNI] Security issues without firewall

From: chamster (chamster@acorn.he.net)
Date: Thu Mar 08 2001 - 18:50:35 CST

  • Next message: chamster: "Re: [LUNI] Security issues without firewall"

    On Thu, 8 Mar 2001, A.Khan wrote:
    > FWIW, Samba can be configured to serve only on specific interface(s) such as
    > 'eth0'. Assuming eth0 is the internal interface of the File-Print
    > Server/NAT/Proxy box. As others have suggested also block the relevant ports
    > on 'ppp0' for additional insurance.

    This is surprisingly undocumented in many Samba guides that you see on the
    Net or in books. I wasn't aware of it until I happened to read about it in
    a Debian mailing list a while back. I tried to find something similar with
    Netatalk and squid. It would make me more comfortable to tell my LAN
    services to say "ignore this interface to the outside world" than to
    say "only allow these IP addresses to connect."

    Steve

    -=-
    Linux Users Of Northern Illinois: General Discussion Mailing list.
    For unsubscription, archives, and announcements only see http://luni.org



    This archive was generated by hypermail 2b29 : Thu Mar 08 2001 - 18:53:01 CST

  •