RE: IPFilter 5.0.5 - some new knobs...

"French, David" <[email protected]>
Newsgroups gmane.comp.security.firewalls.ipfilter
Message-ID <13292_1231240949_49633EF5_13292_20289_1_0B10F79ACCAB6E4B94D9B848F3F63A2E02DA63E7@SDGEXEVS09.corp.intuit.net>
> From: [email protected] 
> [mailto:[email protected]] On Behalf Of Darren Reed
> Sent: Monday, January 05, 2009 7:30 AM
> To: IP Filter
> Subject: IPFilter 5.0.5 - some new knobs...

> New features...and while I've got your attention, what 
> features do you think ipfilter needs that it does not yet have?

Darren, one thing I have wanted--though I don't know how easy it is to
implement--is the ability to pass / block packets based on the user or
group the packet is to/from on the ipfilter host.  That is, block
traffic from user joe going to a specific IP address, network or pool.
Or to say block all incoming traffic to ports not owned by root or
specified users or groups.  The latter would allow me to only allow
traffic into listening daemons run by approved accounts, such as root,
httpd, ftp, etc.  If a user tried to start such a process it would run,
but be inaccessible from outside the box, eliminating users opening
holes I don't want.

Just a thought.  

	--Dave
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.