Re: Can I ignore failing rules?

Benny Pedersen <[email protected]> Wed, 28 Feb 2024 19:36:16 +0100
Newsgroups gmane.comp.security.shorewall
Organization junc.eu
Message-ID <[email protected]>
Peter Thurner | Blunix GmbH via Shorewall-users skrev den 2024-02-28 
17:49:
> Hello shorewall users,
> 
> is there a way to ignore failing rules in shorewall, specifically if 
> /etc/shorewall/rules contains something like
> 
> ACCEPT local pub:this.domain.doesnt.exist.com tcp 443

iptables is not dns based with random ips

stable firewalls should be based on very stable ips

https://sys4.de/blog/abwehr-des-botnets-pushdo-cutwail-ehlo-ylmf-pc-mit-iptables-string-recent-smtp/

this what iptalbes can do

i have forgot how to add this rules to shorewall, hope some will show it 
again