Re: Can I ignore failing rules?

Peter Thurner | Blunix GmbH via Shorewall-users <[email protected]> Wed, 28 Feb 2024 19:47:41 +0100
Newsgroups gmane.comp.security.shorewall
Message-ID <20240228184741.t7bhux6b5e2ygx6k@host>
well thats nice. didnt know that!

my case is a bit different but still VERY interesting post!

On Wed, Feb 28, 2024 at 07:36:16PM +0100, Benny Pedersen wrote:
> Peter Thurner | Blunix GmbH via Shorewall-users skrev den 2024-02-28 17:49:
> > Hello shorewall users,
> > 
> > is there a way to ignore failing rules in shorewall, specifically if
> > /etc/shorewall/rules contains something like
> > 
> > ACCEPT local pub:this.domain.doesnt.exist.com tcp 443
> 
> iptables is not dns based with random ips
> 
> stable firewalls should be based on very stable ips
> 
> https://sys4.de/blog/abwehr-des-botnets-pushdo-cutwail-ehlo-ylmf-pc-mit-iptables-string-recent-smtp/
> 
> this what iptalbes can do
> 
> i have forgot how to add this rules to shorewall, hope some will show it
> again
> 
> 
> 
> 
> 
> 
> _______________________________________________
> Shorewall-users mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/shorewall-users

with kind regards,

Peter Thurner

CEO Blunix GmbH

--

Blunix GmbH
Glogauer Straße 21
10999 Berlin
Germany

Web: https://www.blunix.com