[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [cobalt-users] ipchains installation
- Subject: Re: [cobalt-users] ipchains installation
- From: "Rodolfo J. Paiz" <rpaiz@xxxxxxxxxxxxxx>
- Date: Thu Apr 19 23:48:53 2001
- List-id: Mailing list for users to share thoughts on Cobalt products. <cobalt-users.list.cobalt.com>
At 4/20/01 04:13 PM +0800, you wrote:
I managed to get an ipchains RPM from a RedHat Linux 7.0 CD
(ipchains-1.3.9-17.i386.rpm). Can I install this version of
ipchains into Cobalt?
I don't think so. 7.0 is a new major release and there are
several important changes including the compiler. The RPM's
for 7.0 are different from those for 6.2, so I'd be very
confident that you cannot install that.
Will ipchains affect portsentry if I use default ACCEPT policy?
ipchains will be the first thing on your box to see a packet; Portsentry
will only see what gets passed from there. (Which raises an interesting
question: if only the ports in use are passed by ipchains, but Portsentry
only checks ports that are *not* in use, then what use is Portsentry on a
machine with ipchains?)
Why on Earth would you use a default ACCEPT policy?
--
Rodolfo J. Paiz
rpaiz@xxxxxxxxxxxxxx