[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: help on firewall



When using ip_masquerading, I have seen a friend block machines on his
internal network from using http/ftp/telnet to any address on the outside
using ipfwadm. ie 192.168.1.5 not allowed to use ftp(21), telnet(32) and
http(80) to anywhere by using 0.0.0.0 in the command line or something
similar. Not sure on the exact command line, but have seen him do it. And it
worked well.

/etc/hosts.allow & /etc/hosts.deny is for blocking services/ips coming in..
not going out. or am I wrong?

-----Original Message-----
From: pmiller@jove.acs.unt.edu <pmiller@jove.acs.unt.edu>
To: Wilson Tuma <wilson@fpvc.com>
Cc: debian-user@lists.debian.org <debian-user@lists.debian.org>
Date: Wednesday, 4 November 1998 15:56
Subject: Re: help on firewall


>Wilson Tuma wrote:
>
>> Hi
>>
>> How do I use ipfwadm to prevent  all the users of my local network from
>> doing ftp and telnet to my mail server while allowing only  two other
>> systems the same network from beign able to telnet or ftp to the mail
>> server.
>
>ipfwadm will only filter between networks. You need to take a look at
/etc/hosts.allow
>and /etc/hosts.deny. There is a man page for these files.
>
>--
>Paul Miller
>pmiller@jove.acs.unt.edu
>
>
>
>--
>Unsubscribe?  mail -s unsubscribe debian-user-request@lists.debian.org <
/dev/null
>
>


Reply to: