Networking and the firewall (Was Re: Isn't it time for the encrypted file system???)

Alexander Larsson alexl at redhat.com
Tue Mar 28 07:51:29 UTC 2006


On Mon, 2006-03-27 at 19:54 -0500, David Zeuthen wrote:
> IIRC there were similar issues with SMB browsing and alexl did a
> netfilter kernel module to work around this around the FC3 / RHEL4
> time-frame; not sure it's that easy for g-u-s and the media players.

That was not the same sort of issue. The SMB browse issue was, we send a
UDP multicast packet, and the reply gets filtered because the firewall
doesn't understand the returned packet is a reply. This was fixed by
writing a special connection tracker for such traffic.

The problem with g-u-s is that this really is a server that other people
connect to, which is exactly the kind of thing we enable the firewall to
prevent. 

I must say I'm slightly bothered by the "lets have the apps punch holes
in the firewall" approach. If any app can open holes in the firewall,
what use is the firewall then? It will only be protecting ports that no
application is listening too.

=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
 Alexander Larsson                                            Red Hat, Inc 
                   alexl at redhat.com    alla at lysator.liu.se 
He's a short-sighted amnesiac filmmaker from a doomed world. She's a 
supernatural hip-hop safe cracker fleeing from a Satanic cult. They fight 
crime! 




More information about the Fedora-maintainers mailing list