[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-users] ipchains installation



At 4/20/01 04:13 PM +0800, you wrote:
I managed to get an ipchains RPM from a RedHat Linux 7.0 CD
(ipchains-1.3.9-17.i386.rpm). Can I install this version of
ipchains into Cobalt?

I don't think so. 7.0 is a new major release and there are
several important changes including the compiler. The RPM's
for 7.0 are different from those for 6.2, so I'd be very
confident that you cannot install that.

Will ipchains affect portsentry if I use default ACCEPT policy?

ipchains will be the first thing on your box to see a packet; Portsentry will only see what gets passed from there. (Which raises an interesting question: if only the ports in use are passed by ipchains, but Portsentry only checks ports that are *not* in use, then what use is Portsentry on a machine with ipchains?)

Why on Earth would you use a default ACCEPT policy?


--
Rodolfo J. Paiz
rpaiz@xxxxxxxxxxxxxx