Re: [suse-security] firewall help..
  • From: Maarten J H van den Berg <maarten@xxxxxxx>
  • Date: Tue, 2 Mar 2004 22:48:50 +0100
  • Message-id: <200403022248.50307.maarten@xxxxxxx>
Hi Eric,
Please reply to the list, not to me directly. I read the list. There is no
need to take this off-list.

On Tuesday 02 March 2004 18:21, you wrote:
> Maarten,
> To answer:
> -if you mean allow routing between the networks, yes
> -the ip's I used in the note are examples


> -I did use SuSe firewall2, but my dept. wanted to use iptables instead

Does your dept. realize that SuSEfirewall is just a convenient (and complex)
"wrapper" for iptables ?

> :(

Indeed. Building filters from scratch is difficult. I tend to avoid it when
possible, i.e. use some framework that more or less suits your needs.

> -from anywhere means the internet also. I haven't gotten to the part

Whoa! I don't plan to reeducate your dept. but you really shouldn't be doing
that, not even considering it. What is the goal here ? If it is offering
access to remote offices / staff users then read up on deploying a VPN. If
the goal is offering access to anybody, read up on using other means (http /
ftp / whatever). Just my opinion of course, but my bet is you'll find that
most anybody here will agree with me on this...

I have not looked at your script in detail yet, but it seems to me you maybe
had better rethink your strategy. You cannot "fix" things afterwards with
firewallrules, you need to get it right and logical from the start. For
instance, you need to draft policies. If you are not completely clear on
what you have to do then I would suggest you are not well advised to build
your own filter from scratch.

> where you
> actually start blocking things yet. This is the initial setup.

That approach won't work. That would be akin to checking a door for leakage
when it's open. In other words, if you do use that approach you get
connectivity, but not security.


> Maarten
