Gentoo Logo
Gentoo Spaceship




Note: Due to technical difficulties, the Archives are currently not up to date. GMANE provides an alternative service for most mailing lists.
c.f. bug 424647
List Archive: gentoo-security
Navigation:
Lists: gentoo-security: < Prev By Thread Next > < Prev By Date Next >
Headers:
To: gentoo-security@g.o
From: Matt Drew <matt.drew@...>
Subject: Re: iptables window of opportunity at startup
Date: Sat, 4 Feb 2006 20:16:20 -0500
It is also my experience that iptables will make rules for
non-existent interfaces with no problems.  It may be that you are
seeing the behavior that was modified as a result of bug 78495:

https://bugs.gentoo.org/show_bug.cgi?id=78495

Hotplug made things a little tougher, because of its tendency to bring
up the interface when the module is loaded.  There was some discussion
of this in bugzilla and a decision was made to make it configurable.
The interface coming up on hotplug was desired behavior by some users,
particularly in regard to wireless interfaces.

Admittedly the window is small and not likely to be of use, but it
seems silly to leave it open when it isn't necessary.

On 2/4/06, Mariusz Pękala <skoot@...> wrote:
> On 2006-02-04 13:12:06 +0000 (Sat, Feb), Graham Murray wrote:
> > Jon Mitchell <junk@...> writes:
> >
> > > The current behaviour of a default Gentoo install is to load iptables
> > > after the network has been initialised. Upon shutting down likewise
> > > iptables is shutdown then the network interface. This strikes me as
> > > presenting a window of opportunity when the computer is exposed without
> > > iptables, albeit a small one.
> > >
> > > Do people on this list think there is any value in re-arranging this
> > > order by default?
> >
> > The problem with doing the other way is that iptables rules can
> > reference the specific interfaces to which the rule applies. This will
> > (AFAIK) fail if the interface does not exist when the rule is
> > created. Therefore iptables has to be started after the network.
>
> AFAIK that would not happen.
> You may set a rule for non-existing interface and iptables will not
> fail. If you do have two eth interfaces, try to set a rule for eth4 -
> you will see (I hope) no error. I saw none.
>
> I would vote for starting firewall before network, having my humble
> opinion on that topic. :-)
>
>
> --
> No virus found in this outgoing message.
> Checked by "grep -i virus $MESSAGE"
> Trust me.
>
>
>

-- 
gentoo-security@g.o mailing list


References:
iptables window of opportunity at startup
-- Jon Mitchell
Re: iptables window of opportunity at startup
-- Graham Murray
Re: iptables window of opportunity at startup
-- Mariusz Pękala
Navigation:
Lists: gentoo-security: < Prev By Thread Next > < Prev By Date Next >
Previous by thread:
Re: iptables window of opportunity at startup
Next by thread:
Re: iptables window of opportunity at startup
Previous by date:
Re: iptables window of opportunity at startup
Next by date:
Re: iptables window of opportunity at startup


Updated Jun 17, 2009

Summary: Archive of the gentoo-security mailing list.

Donate to support our development efforts.

Copyright 2001-2013 Gentoo Foundation, Inc. Questions, Comments? Contact us.