Gentoo Archives: gentoo-user

From: Pandu Poluan <pandu@××××××.info>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Do you block outbound ports?
Date: Sun, 21 Aug 2011 04:33:44
Message-Id: CAA2qdGWSp0=Nxcaqq9NbNw7MXEWMXWqyPuJ_1py4d=4QM2nsUw@mail.gmail.com
In Reply to: Re: [gentoo-user] Do you block outbound ports? by Alan McKinnon
1 I can feel for 'just-do-whatever-the-damn-auditor-says-so-he-can-stfu' :)
2
3 I don't really block incoming traffic; instead, I use the TARPIT
4 target (xtables-addons) to make the lifes of portscanners suck ;)
5
6 Rgds,
7
8
9 On 2011-08-21, Alan McKinnon <alan.mckinnon@×××××.com> wrote:
10 > On Sat 20 August 2011 10:38:43 Grant did opine thusly:
11 >> I like the policy of blocking all ports in and out with a firewall
12 >> and only opening the ones you need. Bittorrent makes that
13 >> difficult since it connects out to unpredictable ports. Do you
14 >> block outbound ports with a firewall or only inbound?
15 >
16 > For the most part only inbound. Blocking outbound is pretty much
17 > pointless as a security measure.
18 >
19 > You cannot control what people will want to connect to outbound. Every
20 > time you think you have a complete list, someone will come along and
21 > provide you with heaps of reasons as to why their request is legit
22 > (and it usually is!)
23 >
24 > What you can control completely is the services you offer and on what
25 > ports, therefore inbound firewalls make sense.
26 >
27 > That's not to say we don't use outbound firewalls at all, we do - as a
28 > policy measure. Outbound port 25 is blocked so that people will use my
29 > relays instead. I trust them to play nice, they trust me to keep the
30 > service up. For us, this works well. But as a security measure the
31 > entire model falls apart as soon as someone with a clue comes along. I
32 > have this game I play with our firewall/security people where I get to
33 > look smug. Tool of choice? ssh
34 >
35 > The security benefits from outbound connections to my mind are:
36 > warm-and-fuzzy security
37 > cover-your-ass security
38 > just-do-whatever-the-damn-auditor-says-so-he-can-stfu security
39 > i-don't-know-what-i'm-doing security
40 >
41 > but almost never real security. That's better done with permanent ACLs
42 > on the routers.
43 >
44 > --
45 > alan dot mckinnon at gmail dot com
46 >
47 >
48
49
50 --
51 --
52 Pandu E Poluan - IT Optimizer
53 My website: http://pandu.poluan.info/