1 |
Am Samstag, 4. Februar 2006 13:50 schrieb mir Jon Mitchell: |
2 |
> The current behaviour of a default Gentoo install is to load iptables |
3 |
> after the network has been initialised. Upon shutting down likewise |
4 |
> iptables is shutdown then the network interface. This strikes me as |
5 |
> presenting a window of opportunity when the computer is exposed |
6 |
> without iptables, albeit a small one. |
7 |
> |
8 |
> Do people on this list think there is any value in re-arranging this |
9 |
> order by default? |
10 |
|
11 |
No this doesn't offers a hole, when no service is running and routing is |
12 |
deactivated. So all services have to be started after iptables rules. |
13 |
Same for routing. |
14 |
|
15 |
Iptables doesn't have to protect the TCP/IP stack but a network behind |
16 |
the host or services on that host. |
17 |
|
18 |
Best regards |
19 |
Oli |
20 |
-- |
21 |
gentoo-security@g.o mailing list |