1 |
I can feel for 'just-do-whatever-the-damn-auditor-says-so-he-can-stfu' :) |
2 |
|
3 |
I don't really block incoming traffic; instead, I use the TARPIT |
4 |
target (xtables-addons) to make the lifes of portscanners suck ;) |
5 |
|
6 |
Rgds, |
7 |
|
8 |
|
9 |
On 2011-08-21, Alan McKinnon <alan.mckinnon@×××××.com> wrote: |
10 |
> On Sat 20 August 2011 10:38:43 Grant did opine thusly: |
11 |
>> I like the policy of blocking all ports in and out with a firewall |
12 |
>> and only opening the ones you need. Bittorrent makes that |
13 |
>> difficult since it connects out to unpredictable ports. Do you |
14 |
>> block outbound ports with a firewall or only inbound? |
15 |
> |
16 |
> For the most part only inbound. Blocking outbound is pretty much |
17 |
> pointless as a security measure. |
18 |
> |
19 |
> You cannot control what people will want to connect to outbound. Every |
20 |
> time you think you have a complete list, someone will come along and |
21 |
> provide you with heaps of reasons as to why their request is legit |
22 |
> (and it usually is!) |
23 |
> |
24 |
> What you can control completely is the services you offer and on what |
25 |
> ports, therefore inbound firewalls make sense. |
26 |
> |
27 |
> That's not to say we don't use outbound firewalls at all, we do - as a |
28 |
> policy measure. Outbound port 25 is blocked so that people will use my |
29 |
> relays instead. I trust them to play nice, they trust me to keep the |
30 |
> service up. For us, this works well. But as a security measure the |
31 |
> entire model falls apart as soon as someone with a clue comes along. I |
32 |
> have this game I play with our firewall/security people where I get to |
33 |
> look smug. Tool of choice? ssh |
34 |
> |
35 |
> The security benefits from outbound connections to my mind are: |
36 |
> warm-and-fuzzy security |
37 |
> cover-your-ass security |
38 |
> just-do-whatever-the-damn-auditor-says-so-he-can-stfu security |
39 |
> i-don't-know-what-i'm-doing security |
40 |
> |
41 |
> but almost never real security. That's better done with permanent ACLs |
42 |
> on the routers. |
43 |
> |
44 |
> -- |
45 |
> alan dot mckinnon at gmail dot com |
46 |
> |
47 |
> |
48 |
|
49 |
|
50 |
-- |
51 |
-- |
52 |
Pandu E Poluan - IT Optimizer |
53 |
My website: http://pandu.poluan.info/ |