Re: [SLE] Firewall zones



On Wednesday 27 September 2006 7:17 pm, Anders Johansson wrote:
On Wed, 2006-09-27 at 18:23 -0400, Paul Abrahams wrote:
192.168.0.1/255,tcp,139,udp,137,udp,138

Is 192.168.0.1 an IP address for a single machine, or are you trying to
define a network here? If it's a single machine, skip the / and just use
192.168.0.1. If it's a network, 255 is wrong. The number is the number
of bits in the netmask, most common is 24, for a network where all the
computers share the three first numbers

If it is a single machine, the line should look like

192.168.0.1,tcp,139 192.168.0.1,udp,137 192.168.0.1,udp,138

It's a network, and 192.168.0.0/24 as the value of FW_TRUSTED_NETS did the
trick. That's better than the explicit tcp/udp specification since it
effectively puts that subnet into the internal zone for all services -- just
what I want.

Paul


--
Check the headers for your unsubscription address
For additional commands send e-mail to suse-linux-e-help@xxxxxxxx
Also check the archives at http://lists.suse.com
Please read the FAQs: suse-linux-e-faq@xxxxxxxx



Relevant Pages

  • Re: 6 DAY compile! Any volunteers for distributed build CPU sharing?
    ... marginal as far as making it go faster than on a single machine. ... dedicated build farm and a high speed wired network. ... I have one desktop computer and ... a couple of laptops, and I haven't even bothered trying it. ...
    (comp.sys.mac.programmer.help)
  • Re: Can not use UNC path in Windows server 2003 server 64 bit OS
    ... > For all the net use command I still get the error net work can not be ... > Will Routing and remote access help to set up local network ... > All I need is to use UNC path with single machine that is not ... You can also choose to disable the NIC in the Network Connections window and ...
    (microsoft.public.win2000.dns)
  • Re: Detecting Connection Attempts
    ... > whole network with thousands of systems. ... For the single machine connected to the internet: ... > is a real "technical" benefit of blocking ICMP. ...
    (comp.security.firewalls)
  • Re: Detecting Connection Attempts
    ... > whole network with thousands of systems. ... For the single machine connected to the internet: ... > is a real "technical" benefit of blocking ICMP. ...
    (comp.security.firewalls)
  • Listen up regulars...heres the info.........get rid of the spammer reefbay and his obscene posts
    ... that I forward the headers from his obscene posts, ... Acceptable Use Policy of IN2NET.com ... Network Inc. to users of the In2net services. ... Violations of system or network security are prohibited, ...
    (rec.aquaria.marine.reefs)