1 |
On Thu, February 23, 2012 12:25 pm, Alan McKinnon wrote: |
2 |
> Just don't do what I did earlier: sit in Joburg and configure the |
3 |
> firewall on a Xen host in deepest darkest Africa where there's no |
4 |
> tarred roads to get to it. |
5 |
|
6 |
How did you get the server there? Flown it in? |
7 |
I've seen the roads in Africa and those are difficult to navigate... |
8 |
(The tarmac'd ones are decent though) |
9 |
|
10 |
> Check the iptables config three times, |
11 |
> plus get your colleagues to look it over as well. We all signed off on |
12 |
> it. |
13 |
> |
14 |
> Guess what? Yup, you got it. We all missed something and now we are |
15 |
> locked out. Remember, it's in deepest darkest Africa. |
16 |
|
17 |
That's why I like the "ADMINISABSENTMINDED" option in the Shorewall |
18 |
config. It doesn't kill existing connections. |
19 |
|
20 |
I always test a new remote connection prior to closing the one I used to |
21 |
change it with. |
22 |
If I do accidentally kill my existing connection, the "safe_restart" |
23 |
option will cause it to roll-back if I don't accept the new settings |
24 |
before a time-out. |
25 |
|
26 |
-- |
27 |
Joost |