1 |
What about a configuration packages? I think that the default settings of an ebuild should be conservative and secure, but when you start talking about ebuilds with lots of configuration options you see a need for a what Chad is talking about. How about: |
2 |
|
3 |
emerge rusty_impervious_firewall.x.y.z.econf |
4 |
|
5 |
or maybe it should be a separate tool: |
6 |
|
7 |
econfig tonys_sweet_gnome_setup.x.y.z.econf |
8 |
|
9 |
That way we can keep configuration and installation in separation. |
10 |
|
11 |
-sherman |
12 |
|
13 |
|
14 |
-----Original Message----- |
15 |
From: Chad Huneycutt <chad.huneycutt@×××.org> |
16 |
Sent: Monday, October 01, 2001 7:30 PM |
17 |
To: <gentoo-dev@××××××××××.org> |
18 |
Subject: Re: [gentoo-dev] NAT iptables info |
19 |
|
20 |
|
21 |
|
22 |
Donny Davies wrote: |
23 |
|
24 |
>To provide some kind of gentoo firewall is, hmm, well silly. Its %100 |
25 |
>configuration. This is not the domain of a 'package', 'rpm' or ebuild. |
26 |
> |
27 |
I don't completely agree with this. While questions like "How do I set |
28 |
up a firewall?" are not completely germaine to this mailing list, the |
29 |
above statement is your opinion and open for discussion here. I think |
30 |
that it is a very good idea to provide several basic scripts for common |
31 |
configurations. If they are already out there, then great!, we should |
32 |
include them in an ebuild. It is a much better policy to have the |
33 |
network default to a secure state (such as the Rusty's script that |
34 |
allows no incoming connections) than to leave it wide open, and let the |
35 |
potentially newbie sysadmin get hacked. |
36 |
|
37 |
It would be nice to bring up a semi secure, masquerading (or whatever |
38 |
they are calling it these days) firewall box with little effort. From |
39 |
there, one can learn about iptables and such things to customize it further. |
40 |
|
41 |
Just some thoughts from someone who hasn't delved into iptables yet, |
42 |
|
43 |
Chad |
44 |
|
45 |
|
46 |
_______________________________________________ |
47 |
gentoo dev mailing list |
48 |
gentoo dev@××××××××××.org |
49 |
http://cvs.gentoo.org/mailman/listinfo/gentoo dev |