Re: CLOSING a web server!!!!!!

On Fri, 7 Feb 2003, [iso-8859-1] Iñaki Martínez wrote:

> > >   21 -> only from my fix IP
> > 
> > Use scp.  FTP requires some very b0rken firewalling.
>  OK...... and about SFTP?????
>  Some of the webmaster are using windows FTP clients, so i need FTP or SFTP.

Give them something else.  There are plenty of point-and-drool SCP clients
out there, that work just like CuteFTP or WussFTP or whatever they're using.

>  What i mean is:
>  global -> allow-query = only my IPs
>  per domain -> allow-query any

If you're wanting to do what I think you're wanting to do, it's not a
firewall issue, since the firewall shouldn't be doing deep magic within
protocols (that's up to the daemon in question).

> > >  What are the BETTER and MORE SECURE iptables rules for this server????
> > 
> > Those above work for me.
>  OK, but what about  "-m state --state NEW" or similar????

Use 'em if you need 'em.  They have their uses, like if you want to only
allow connections in one direction or some other crazy stuff.  But most of
the time you'll do just fine with the regular ones.

#include <disclaimer.h>
Matthew Palmer, Geek In Residence

