Gentoo Archives: gentoo-security

From: Francois Toussenel <wednews@××××××.fr>
To: gentoo-security@l.g.o
Subject: Re: [gentoo-security] iptables window of opportunity at startup
Date: Tue, 07 Feb 2006 17:22:20
Message-Id: 20060207181625.084470ca@san.toussenel.org
In Reply to: Re: [gentoo-security] iptables window of opportunity at startup by Tobias Klausmann
1 On Sun, 5 Feb 2006 13:29:55 +0100 Tobias Klausmann <klausman@××××××××××××.de> wrote:
2
3 > Which *should* make iptables start before net.* (maybe except
4 > net.lo). And sure enough, the boot sequence is:
5
6 This depends on the runlevels in which you have iptables and net.eth0.
7 Could you please post the output of the following command?
8
9 # rc-update show | grep 'iptables\|net\.'
10
11 By having iptables in boot and net.eth0 in default, iptables starts
12 before net.eth0, but it also stops before services and of course
13 net.eth0. Does somebody know a setting to avoid that?
14
15 (I would add that one might want to never respond to pings, for
16 instance, so starting iptables between net.eth0 and services seems not
17 enough.)
18
19 Regards,
20
21 Francois
22 --
23 gentoo-security@g.o mailing list

Replies

Subject Author
Re: [gentoo-security] iptables window of opportunity at startup xyon <xyon@×××××××××××.com>
Re: [gentoo-security] iptables window of opportunity at startup Tobias Klausmann <klausman@××××××××××××.de>