Re: [sanewall-dev] Changing activation policy
Thomas Arendsen Hein <[email protected]>
| Newsgroups | gmane.comp.security.firewalls.firehol.devel,gmane.comp.security.firewalls.firehol.user |
|---|---|
| Message-ID | <[email protected]> |
* Phil Whineray <[email protected]> [20120519 18:53]: > For sanewall I think I should change the activation policy for the > FORWARD chain from ACCEPT TO DROP. > > Could people please let me know if this will adversely affect them and > if possible test what effect it has? > > Just add to the top of your config: > SANEWALL_FORWARD_ACTIVATION_POLICY=DROP > > If you are using firehol the equivalent would be to add: > FIREHOL_FORWARD_ACTIVATION_POLICY=DROP > > There are two other policies for INPUT and OUTPUT, also set to ACCEPT > during activation. This as-designed, to avoid intefering with establish > connections whilst restarting and eliminated the risk that the host becomes > inaccessible to the admin if something goes wrong whilst restarting the > firewall remotely. I am using DROP on INPUT/OUTPUT/FORWARD since 2003 on multiple (40-60?) hosts and absolutely never had a disconnect of the ssh session I used to activate the rules, even with very large rulesets, where it took up to 5 minutes to activate >5000 rules across many interfaces. See my very old bug report about this: http://sourceforge.net/tracker/?func=detail&atid=487695&aid=756001&group_id=58425 Therefore I suggest setting it to DROP for all three activation policies. Regards, Thomas -- [email protected] - http://intevation.de/~thomas/ - OpenPGP key: 0x5816791A Intevation GmbH, Neuer Graben 17, 49074 Osnabrueck - AG Osnabrueck, HR B 18998 Geschaeftsfuehrer: Frank Koormann, Bernhard Reiter, Dr. Jan-Oliver Wagner ------------------------------------------------------------------------------ Live Security Virtual Conference Exclusive live event will cover all the ways today's security and threat landscape has changed and how IT managers can respond. Discussions will include endpoint security, mobile security and the latest in malware threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ _______________________________________________ Firehol-devs mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/firehol-devs
signature.asc
(application/pgp-signature, 198 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iEYEABECAAYFAk+57GQACgkQW7P1GVgWeRqSkACfRoRUln6SI6Hz5yEOFcg5GlbK p4gAnj3K0RLT1XOL+ftl1cXElSyVDPCz =zGCt -----END PGP SIGNATURE-----