*BSD News Article 89583


Return to BSD News archive

Path: euryale.cc.adfa.oz.au!newshost.carno.net.au!harbinger.cc.monash.edu.au!lucy.swin.edu.au!news.rmit.EDU.AU!goanna.cs.rmit.edu.au!news.apana.org.au!cantor.edge.net.au!news.teragen.com.au!news.access.net.au!news.mel.connect.com.au!munnari.OZ.AU!spool.mu.edu!howland.erols.net!rill.news.pipex.net!pipex!tank.news.pipex.net!pipex!news.utell.co.uk!ui-gate.utell.co.uk!brian
From: brian@ui-gate.utell.co.uk (Brian Somers)
Newsgroups: comp.os.linux.misc,comp.os.linux.networking,comp.unix.bsd.freebsd.misc
Subject: Re: Free firewall?
Followup-To: comp.os.linux.misc,comp.os.linux.networking,comp.unix.bsd.freebsd.misc
Date: 17 Feb 1997 18:15:26 GMT
Organization: Utell International
Lines: 28
Message-ID: <5ea77u$j8p@ui-gate.utell.co.uk>
References: <330333EF.48C8@usa.net> <3304B369.65DB687B@ibm.net>
NNTP-Posting-Host: ui-gate.utell.net
X-Newsreader: TIN [version 1.2 PL2]
Xref: euryale.cc.adfa.oz.au comp.os.linux.misc:159532 comp.os.linux.networking:68999 comp.unix.bsd.freebsd.misc:35718

Jan Walter (jnwal@ibm.net) wrote:

: Firewalling is built into linux as well. Toolkits and other stuff
: basically extend or complement that capability.

Forgive the ignorant question, but what is a firewalling product ?  Is
it something that tries to put a front end on a list of ipfw calls ?
Sounds horrible to me - surely it's worth knowing what's going on
when you build a firewall ?

I guess if the software does validity checks and comes up with things
like "anyone can telnet in and user xxx has no password"....

: Linux can also translate network addresses at the kernel level, where
: every system behind the linux box actually accesses the net using the
: linux box's IP address. It's just an extension of the firewalling
: function.

Yep, except that you're usually better off with a proxy.  With NAT,
you never quite get things like RPC right - not to mention having
difficulty with ftp & irc and the like.

I'm not against NAT, it just infuriates me ;)

--
Brian <brian@awfulhak.demon.co.uk> <brian@utell.co.uk> <brian@freebsd.org>
      <http://www.awfulhak.demon.co.uk>
Don't _EVER_ lose your sense of humour !