From owner-freebsd-security Wed Jun 20 18:18:36 2001 Delivered-To: freebsd-security@freebsd.org Received: from famine.OCF.Berkeley.EDU (famine.OCF.Berkeley.EDU [128.32.191.92]) by hub.freebsd.org (Postfix) with ESMTP id 1338D37B406 for ; Wed, 20 Jun 2001 18:18:34 -0700 (PDT) (envelope-from malcolm@ocf.berkeley.edu) Received: from localhost (malcolm@localhost) by famine.OCF.Berkeley.EDU (8.9.3/8.9.3) with ESMTP id SAA23570 for ; Wed, 20 Jun 2001 18:18:33 -0700 (PDT) X-Authentication-Warning: famine.OCF.Berkeley.EDU: malcolm owned process doing -bs Date: Wed, 20 Jun 2001 18:18:33 -0700 (PDT) From: Malcolm To: Subject: IPFilter and security Message-ID: MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org Hi folks, What do we think about installing IPFilter on non-gateway boxes and using it to block all incoming traffic except for whatever ports we want to use on our server (e.g., http, ftp)? Thanks, Malcolm To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message