Gentoo Archives: gentoo-user

From: Dave S <gentoo@××××××××.net>
To: Gentoo list <gentoo-user@l.g.o>
Subject: [gentoo-user] OT 0.0.0.0 security query
Date: Sat, 27 May 2006 09:49:01
Message-Id: 200605271040.52377.gentoo@pusspaws.net
1 Hi all,
2
3 This is a bit OT but I have a netgear router DG834 ADSL firewall router. I
4 have restricted my incoming services with ...
5
6 Enable Service Name Action LAN Server IP address WAN Users Log
7 on bit torrent ALLOW always 192.168.0.5 Any Always
8 Default Yes Any BLOCK always Any Any Never
9
10 And tightened my outgoing services with ...
11
12 Enable Service Name Action LAN Users WAN Servers Log
13 on HTTP ALLOW always Any Any Always
14 on HTTPS ALLOW always Any Any Always
15 on POP ALLOW always Any Any Always
16 on SMTP ALLOW always Any Any Always
17 on NTP ALLOW always Any Any Always
18 on FTP ALLOW always Any Any Always
19 on rsync ALLOW always Any 0.0.0.0 Never
20 on GM Port 389 ALLOW always 192.168.0.6 Any Always
21 on GM Port 1503 ALLOW always 192.168.0.6 Any Always
22 on GM Port 1731 ALLOW always 192.168.0.6 Any Always
23 on GM 1024-65K ALLOW always 192.168.0.6 Any Always
24 on H.323 ALLOW always 192.168.0.6 Any Always
25 on Port >1023 ALLOW always Any Any Always
26 on Samba ALLOW always Any 0.0.0.0 Always
27 on samba2 ALLOW always Any 0.0.0.0 Always
28 on samba3 ALLOW always Any 0.0.0.0 Always
29 on Any(ALL) BLOCK always Any Any Always
30 Default Yes Any ALLOW always Any Any
31
32 Some services like rsync and samba I want to keep within my LAN but my DG834
33 insists I give it a least one IP address on the WAN that my service can be
34 broadcast to. I selected 0.0.0.0
35
36 Can anyone advise, am I going about this the right way, any comment greatly
37 appreciated :)
38
39 Cheers
40
41 Dave
42 --
43 gentoo-user@g.o mailing list

Replies

Subject Author
Re: [gentoo-user] OT 0.0.0.0 security query Jonathan Chocron <jonathan.chocron@××××.fr>