mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: "Michael H. Warfield" <mhw@wittsend.com>
To: David Lang <david.lang@digitalinsight.com>
Cc: Michael Rothwell <rothwell@holly-springs.nc.us>,
	"Michael H. Warfield" <mhw@wittsend.com>,
	linux-kernel@vger.kernel.org
Subject: Re: iptables: "stateful inspection?"
Date: Wed, 20 Dec 2000 12:13:51 -0500	[thread overview]
Message-ID: <20001220121351.D10408@alcove.wittsend.com> (raw)
In-Reply-To: <3A40DE97.96228B5E@holly-springs.nc.us> <Pine.LNX.4.31.0012200848430.180-100000@dlang.diginsite.com>
In-Reply-To: <Pine.LNX.4.31.0012200848430.180-100000@dlang.diginsite.com>; from david.lang@digitalinsight.com on Wed, Dec 20, 2000 at 08:51:34AM -0800

On Wed, Dec 20, 2000 at 08:51:34AM -0800, David Lang wrote:
> On Wed, 20 Dec 2000, Michael Rothwell wrote:

> > Date: Wed, 20 Dec 2000 11:30:15 -0500
> > From: Michael Rothwell <rothwell@holly-springs.nc.us>
> > To: Michael H. Warfield <mhw@wittsend.com>
> > Cc: linux-kernel@vger.kernel.org
> > Subject: Re: iptables: "stateful inspection?"

> > "Michael H. Warfield" wrote:
> > >         I think that's more than a little overstatement on your
> > > part.  It depends entirely on the application you intend to put
> > > it to.

> > Fine. How do I make FTP work through it? How can I allow all outgoing
> > TCP connections without opening the network to inbound connections on
> > the ports of desired services?
> >

> for the issue of outbound TCP connections you can set ipchains filters
> based on the Syn flag to prevent inbound connections.

> for FTP I don't know off the top of my head how to do it when not
> masquerading, when NAT is turned on load the FTP masq helper module and it
> will allow you to do ftp out with no problems.

	You can use spf to add some stateful inspection for PORT mode
ftp.  Personally, I like the masquerading option better, though.

> the real point that you need the stateful filtering is on UDP ports. for
> that again I don't know any way when not doing NAT, but when NAT is
> enabled it does do basic stateful filtering (but watch out for timeouts)

	Stateful filter also helps block FIN scans and other stealth
scans, as well as some other esoteric attacks (fragmentation attacks,
Ping'O Death, etc...).  There are other ways to deal with those attacks
as well, but stateful filtering helps.  You also need it if you want to
take advantage of some ICMP as well.

	Big thing for me about NetFilter over IPChains, in addition to
statefull inspection, is the fact that we finally have an IPv6 aware
firewall now.  I've been chomping at the bit to get on IPv6 but
couldn't till I had working firewall code for that.

> David Lang

> > >         Yes it does.  It's clearly stated in all the documentation
> > > on netfilter and in it's design.  Read the fine manual (or web site)
> > > and you would have uncovered this (or been run over by it) for yourself.
> > >
> > >         http://netfilter.filewatcher.org/
> >
> > Thanks.
> >
> > -M

	Mike
-- 
 Michael H. Warfield    |  (770) 985-6132   |  mhw@WittsEnd.com
  (The Mad Wizard)      |  (678) 463-0932   |  http://www.wittsend.com/mhw/
  NIC whois:  MHW9      |  An optimist believes we live in the best of all
 PGP Key: 0xDF1DD471    |  possible worlds.  A pessimist is sure of it!

-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
Please read the FAQ at http://www.tux.org/lkml/

  reply	other threads:[~2000-12-20 17:44 UTC|newest]

Thread overview: 18+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2000-12-20 16:18 Michael Rothwell
2000-12-20 16:25 ` Michael H. Warfield
2000-12-20 16:30   ` Michael Rothwell
2000-12-20 16:51     ` David Lang
2000-12-20 17:13       ` Michael H. Warfield [this message]
2000-12-20 17:52         ` Michael Rothwell
2000-12-20 18:08           ` Michael H. Warfield
2000-12-20 18:38             ` Michael H. Warfield
2000-12-20 17:08     ` Michael H. Warfield
2000-12-20 20:45     ` Alan Cox
2000-12-20 20:51       ` Michael Rothwell
2000-12-20 22:02         ` Dax Kelson
2000-12-21  0:44         ` Alan Cox
2000-12-21  2:26           ` Laptop system clock slow after suspend to disk. (2.4.0-test9/hinote VP) Ian Stirling
2000-12-21 22:05             ` Keith Owens
2000-12-21  2:37           ` iptables: "stateful inspection?" Michael Rothwell
2000-12-21  7:00     ` George
     [not found] ` <20001222140517.A30215@convergence.de>
2000-12-22 15:42   ` Michael Rothwell

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20001220121351.D10408@alcove.wittsend.com \
    --to=mhw@wittsend.com \
    --cc=david.lang@digitalinsight.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=rothwell@holly-springs.nc.us \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®