[md@Linux.IT (Marco d'Itri)] Re: Required firewall support

Here's one fellow's interpretation of that requirement.  

On Mar 17, Thomas Bushnell BSG <tb@becket.net> wrote:

> > > One of the conditions for SCC is "fully functioning Unix, including
> > > DNS and firewall support."  What specifically is intended by "firewall
> > > support"?  
> > I think that simple ACLs are the bare minimum.
> Ok, can you point me at the specific feature, and why is this feature
I think that the minimum is per-interface permit/deny ACLs which could
match at least on IP protocol number, TCP/UDP ports and ICMP types.

> important for packaging in SCC?
Because Debian should not waste resources to support a toy OS (in this
case defined as one not secure enough to stay on the internet for real


