Mailing List Archive
tlug.jp Mailing List tlug archive tlug Mailing List Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][tlug] Re: SuSE CD problem (was SuSE 8.0 copies at TLUG meeting)
- Date: Thu, 16 May 2002 14:30:27 +0200
- From: Mike Fabian <mfabian@example.com>
- Subject: [tlug] Re: SuSE CD problem (was SuSE 8.0 copies at TLUG meeting)
- References: <20020515164222.K13130@example.com><Pine.SUN.3.95.1020516024917.18929B-100000@example.com><20020516105640.D19428@example.com>
- User-agent: Gnus/5.090004 (Oort Gnus v0.04) XEmacs/21.4 (Common Lisp,i386-suse-linux)
Jonathan Q <jq@example.com> writes: > I've dabbled a bit in SuSE 8 now, and while it's pretty good, my > first impressions are: [...] > 3) Two many scripts for firewalling and the graphical firewall config > tool is not nearly fine-grained enough (being able to specify port > 22 open is too coarse; the user should be able to specify from which > addresses port 22 connections will be accepted). Mandrake is also guilty > of this sin, and it's one of the reasons I dumped Mandrake. > Red Hat's approach to this is best; they use lokkit to > generate /etc/sysconfig/ipchains, and that is an ASCII file containing > rules for ipchains. Lokkit doesn't give a fine-grained approach > either, but you can whip out your favorite editor and modify that > file directly. On SuSE you have fine grained control by editing /etc/sysconfg/SuSEfirewall2 manually. Specifying from which addresses port 22 connections will be accepted is possible by setting: FW_TRUSTED_NETS="a.b.c.d/mask,tcp,22" This file appears to have a lot of helpful comments, it looks like many other detailed settings are possible. -- Mike Fabian <mfabian@example.com> http://www.suse.de/~mfabian 睡眠不足はいい仕事の敵だ。
- References:
- Re: [tlug] SuSE CD problem (was SuSE 8.0 copies at TLUG meeting)
- From: Jonathan Q
- Re: [tlug] SuSE CD problem (was SuSE 8.0 copies at TLUG meeting)
- From: Nguyen Hung Takeshi
- Re: [tlug] SuSE CD problem (was SuSE 8.0 copies at TLUG meeting)
- From: Jonathan Q
Home | Main Index | Thread Index
- Prev by Date: [tlug] init cannot write to /dev/initctl
- Next by Date: Re: [tlug] Apple's new 1U dual G4 rackmount
- Previous by thread: [tlug] Re: SuSE CD problem (was SuSE 8.0 copies at TLUG meeting)
- Next by thread: [tlug] Linux rack servers
- Index(es):
Home Page Mailing List Linux and Japan TLUG Members Links