Re: Filtering on Ether type, not port

Matt Darfeuille <[email protected]>
Newsgroups gmane.comp.security.shorewall
Message-ID <[email protected]>
On 3/2/2022 4:47 PM, Peter Humphrey wrote:
> Thank you Ruth.
> 
> On Wednesday, 2 March 2022 15:29:50 GMT Ruth Ivimey-Cook wrote:
>> I wouldn't bother trying to filter on type, just filter on either FB's
>> (Mac or IP) address (and possibly dest IP) + port as well.
> 
> SW on my LAN server is dropping all incoming packets to port 80, which in this
> case just pollutes the log.
> 

Maybe you could take some inspiration from (1).

> 
> Should I be nervous about opening port 80 to the FB? Won't that just allow
> packets in from the Internet?
> 

I would say no but it realy depends on how the FB is configured.

1)  https://shorewall.org/shorewall_logging.html

-- 
Matt Darfeuille <[email protected]>
Community: https://sourceforge.net/p/shorewall/mailman/message/37107049/
SPC: https://sourceforge.net/p/shorewall/mailman/message/36596609/
Homepage: https://shorewall.org
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.