1 |
> > It occurred to me that if the shorewall firewall on my headless router |
2 |
> > doesn't start for whatever reason, I'll be totally exposed. Is there |
3 |
> > a way to protect against that? |
4 |
> |
5 |
> Well, you'll get an error during boot that iptables did not come up. |
6 |
|
7 |
The machine is headless though. |
8 |
|
9 |
> I assume that shorewall is only run when you change the script and |
10 |
> otherwise /etc/init.d/iptables is run as a default service after boot. |
11 |
|
12 |
Ouch. No. I'm running shorewall in the default runlevel and iptables |
13 |
explicitly not at all. I thought running shorewall was all I needed |
14 |
to do. Can you confirm that I should be running iptables in the |
15 |
default runlevel and shorewall only when I want to update the config? |
16 |
|
17 |
> Anyway, a closed port remains closed whether a firewall is running, or not. |
18 |
|
19 |
I thought the firewall specified which ports to open/close. |
20 |
|
21 |
- Gramt |
22 |
-- |
23 |
gentoo-user@g.o mailing list |