Re: [Security-Discuss] MDK Update And Shorewall

Anton Aylward <[email protected]>
Newsgroups gmane.linux.mandrake.security.general
Organization System Integrity
Message-ID <[email protected]>
On Wed, 2004-09-22 at 11:07, Matt Parker wrote:
> Yes, but I, and most sensible people would IMO, read that as meaning that 
> Shorewall would need to be restarted after the upgrade. It does not say that 
> the firewall will be down for the duration of the upgrade process leaving you 
> open to attack in the meantime.

I'm sorry, Matt, I don't see it that way.
The situation you describe only holds if, when Shorewall is off, the
firewall machine acts as an open router to the internal network, AND the
internal network is not RFC1918 ... and you haven't customized any
IPTables commands ...

The Shorewall documentation does describe the difference between 'stop'
and 'clear': http://www.shorewall.net/FAQ.htm#faq7 and
http://wiki.rettc.com/wiki.phtml?title=Starting_and_Stopping

See also http://www.shorewall.net/1.4/

Remember, what shorewall does is ALTER the kernel tables.  

-- 
Anton J Aylward, [email protected]
Marketing is the science of convincing us that What You Get Is What You
Want. 
  -- John Carter
message.footer (text/plain, 239 B)
____________________________________________________
Want to buy your Pack or Services from MandrakeSoft? 
Go to http://www.mandrakestore.com
Join the Club : http://www.mandrakeclub.com
____________________________________________________
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.