Re: Ports to block?

It's better to do it this way:

ipchains -P input DENY

ipchains -A input -s (source add./port) -d (dest. add./port) -j ACCEPT

. . . (acceptance rules)

ipchains -A input -j DENY -l (logs all stuff not ACCEPTed above).

I also put other DENY statements on top of the last logging DENY for things I don't care to log. The syslog will fill up rapidly with insignificant crap if you don't (I had my colo fill /var with sputter from a misconfigured router once).

The reason you start out with a DENY is so that there is no chance of a packet coming through before all of the chains are parsed. Also a good idea is to build the chains before bringing up the interface(s).

Haphazard security is marginally second to no security at all.

