Re: [sanewall-dev] Changing activation policy

Thomas Arendsen Hein <[email protected]>
Newsgroups gmane.comp.security.firewalls.firehol.devel,gmane.comp.security.firewalls.firehol.user
Message-ID <[email protected]>
* Phil Whineray <[email protected]> [20120519 18:53]:
> For sanewall I think I should change the activation policy for the
> FORWARD chain from ACCEPT TO DROP.
> 
> Could people please let me know if this will adversely affect them and
> if possible test what effect it has?
> 
> Just add to the top of your config:
>   SANEWALL_FORWARD_ACTIVATION_POLICY=DROP
> 
> If you are using firehol the equivalent would be to add:
>   FIREHOL_FORWARD_ACTIVATION_POLICY=DROP
> 
> There are two other policies for INPUT and OUTPUT, also set to ACCEPT
> during activation. This as-designed, to avoid intefering with establish
> connections whilst restarting and eliminated the risk that the host becomes
> inaccessible to the admin if something goes wrong whilst restarting the
> firewall remotely.

I am using DROP on INPUT/OUTPUT/FORWARD since 2003 on multiple
(40-60?) hosts and absolutely never had a disconnect of the ssh
session I used to activate the rules, even with very large rulesets,
where it took up to 5 minutes to activate >5000 rules across many
interfaces.

See my very old bug report about this:
http://sourceforge.net/tracker/?func=detail&atid=487695&aid=756001&group_id=58425

Therefore I suggest setting it to DROP for all three activation
policies.

Regards,
Thomas

-- 
[email protected] - http://intevation.de/~thomas/ - OpenPGP key: 0x5816791A
Intevation GmbH, Neuer Graben 17, 49074 Osnabrueck - AG Osnabrueck, HR B 18998
Geschaeftsfuehrer: Frank Koormann, Bernhard Reiter, Dr. Jan-Oliver Wagner

------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/

_______________________________________________
Firehol-devs mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/firehol-devs
signature.asc (application/pgp-signature, 198 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iEYEABECAAYFAk+57GQACgkQW7P1GVgWeRqSkACfRoRUln6SI6Hz5yEOFcg5GlbK
p4gAnj3K0RLT1XOL+ftl1cXElSyVDPCz
=zGCt
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.