1 |
On Sat, Aug 20, 2011 at 12:38 PM, Grant <emailgrant@×××××.com> wrote: |
2 |
> I like the policy of blocking all ports in and out with a firewall and |
3 |
> only opening the ones you need. Bittorrent makes that difficult since |
4 |
> it connects out to unpredictable ports. Do you block outbound ports |
5 |
> with a firewall or only inbound? |
6 |
|
7 |
I don't block anything outbound, but my ISP does (mostly MS-stuff that |
8 |
I don't care about). I do, however, occasionally block all outgoing |
9 |
just to see what the logs show, so I'm aware of what's happening. But |
10 |
I don't actively monitor that outbound traffic. |
11 |
|
12 |
I block everything inbound and only open what's specifically needed. I |
13 |
use denyhosts and fail2ban to block bad guys from all ports. |