Re: Ports to block?

 Thu, Apr 05, 2001 at 09:38:46PM +0100, Steve Ball wrote:

> It is most secure to block everything and only open the ports that are 
> absolutely necessary.
ok, this is clear. What's the way you ppl do that throught ipchains/iptables
? Is it better to use the ACCEPT policy and then DENY all or use the DENY
policy and ACCEPT only ports needed ? I use the first 'cause so I can log
all packet that are denied...

# Start
ipchains -P input ACCEPT
ipchains -A input -j DENY -l
# End


