[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Security: FreeBSD vs OpenBSD



--- Luiz Gustavo <gustavo@shoptime.com> wrote:
> On Mon, Feb 04, 2002 at 03:43:03PM -0200,
> rss@cin.ufpe.br wrote:
>  
> > >  I dont think abuse of rdr on servers looks
> good, why you will need
> > >  pf *running* on every server?
>  
> > There is no problem to do it. There is no problem
> to abuse
> > redirect. Do you have a better solution?
> 
>  Have every machine in your network running IPF or
> PF looks a bit
>  wacky to me, thats why everyone have some real
> configured  fws
>  around.
>  Daemons should handle access limits or use
> tcpwrapper/daemontools.
>  Running in a lots of machines, give me a break.
> Dont scale.
>  Anyway Im open for ideas. :)
> 
> Gustavo

Wacky idea #1 - SSH into clients and change IPF or PF
rulesets with an Expect script.  Haven't done it but
it popped into my head.


=====
-----------------------------------------------------------
Few people think more than two or three times a year;
I have made an international reputation for myself by 
thinking once or twice a week.
                                      George Bernard Shaw
-----------------------------------------------------------
Great stuff seeking new owners in Yahoo! Auctions! 
http://auctions.yahoo.com