[Bug 272516] New: SuSEfirewall2 unexpected default FW_SERVICES_REJECT_EXT configuration
https://bugzilla.novell.com/show_bug.cgi?id=272516 Summary: SuSEfirewall2 unexpected default FW_SERVICES_REJECT_EXT configuration Product: SUSE Linux 10.1 Version: Final Platform: Other OS/Version: Other Status: NEW Severity: Normal Priority: P5 - None Component: Security AssignedTo: security-team@suse.de ReportedBy: s.handgraaf@xs4all.nl QAContact: qa@suse.de SUSE has a state of the art firewall build around the purpose only to cooperate with outside traffic when needed by the user. Except on one point: the handling of ident traffic on port 113. By default the firewall is configured to ignore any need and just answer the outside traffic with a reject. Configuration /etc/sysconfig/SuSEfirewall2 : FW_SERVICES_REJECT_EXT="0/0,tcp,113" Imho a firewall should not be configured this conflicting way. A firewall is implemented for security. Security is based on protecting the users interests. My main point is a system should not be configured to answer requests to non existing services unless the user explicitly needs this by a confirmation. My suggestions are as follows: a) remove the rule to reject so all requests from outside are droped by default b) only configure the firewall to reject instead of drop traffic when the users confirms this; c) configure the firewall to drop by default but reject traffic when it can be expected this was triggered from inside when the users confirms it wants this behaviour, otherwise drop all traffic. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
https://bugzilla.novell.com/show_bug.cgi?id=272516 lnussel@novell.com changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |RESOLVED Resolution| |WONTFIX ------- Comment #1 from lnussel@novell.com 2007-05-09 01:21 MST ------- ident is not dropped by default to avoid timeouts with e.g. SMTP and IRC servers. I don't know whether such broken SMTP servers are still common. On IRC servers at last the misbehavior of quering ident still seems to be used. So I'll keep the current default configuration for another few releases. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
https://bugzilla.novell.com/show_bug.cgi?id=272516 ------- Comment #2 from s.handgraaf@xs4all.nl 2007-05-09 04:46 MST ------- (In reply to comment #1)
ident is not dropped by default to avoid timeouts with e.g. SMTP and IRC servers. I don't know whether such broken SMTP servers are still common. On IRC servers at last the misbehavior of quering ident still seems to be used. So I'll keep the current default configuration for another few releases.
Is there any motivation to make this as only port by default reject while others are droped from a security perspective? As I mentioned, imho in the first place a firewall is here to protect. Starting with the motivation it might be needed for some users since some unknown percentage can have some minor trouble does not fit common security perspective. I think the only good reason to put a default reject in is if users truely need this en mass. That is also why all other ports are droped by default. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
participants (1)
-
bugzilla_noreply@novell.com