Jon Galt on Tue, 26 Feb 2002 04:40:09 +0100


[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]

[PLUG] fire wall question(s)


Hi all, I'm discussing the need for a firewall with a friend of mine who
has DSL and connects a Win2K box and a Linux box to it via a hub.  He
agrees with me that a firewall is good for segregating the LAN traffic
from the outside world.  (For example, having ftpd running on my Linux
box, but not allowing anybody outside the firewall to make ftp connections
in.)

But here's a scenario he has suggested:
"But still I suppose that if you had a dedicated server, say
for HTTP, then your machine has no business listening to
anything except HTTP coming in on port 80.  If you set it up
so that it responds only to HTTP on port 80, then a firewall
between it and the Internet could not add anything but delay. 
Assuming, that is, that I know what I'm talking about."

Any comments on this?

Also, I'm curious about his ip configuration.

"Windows 2000 IP Configuration

Ethernet adapter Local Area Connection:

        Connection-specific DNS Suffix  . :
        IP Address. . . . . . . . . . . . : 192.168.0.1
        Subnet Mask . . . . . . . . . . . : 255.255.255.0
        Default Gateway . . . . . . . . . :

PPP adapter WinPoET Connection:

        Connection-specific DNS Suffix  . :
        IP Address. . . . . . . . . . . . : 63.173.123.25
        Subnet Mask . . . . . . . . . . . : 255.255.255.255
        Default Gateway . . . . . . . . . : 63.173.123.25"

Is that two separate interfaces, or is the PPP over Ethernet (WinPoET)
adapter using the local ethernet that is listed?

He didn't send the ifconfig info on his Linux box.

Just trying to learn more about network/security issues.

Thanks,
Wayne


______________________________________________________________________
Philadelphia Linux Users Group       -      http://www.phillylinux.org
Announcements-http://lists.phillylinux.org/mail/listinfo/plug-announce
General Discussion  -  http://lists.phillylinux.org/mail/listinfo/plug