Re: Firewalls, are they really necessary?

From: Fao, Sean (enceladus311_at_yahoo.comI-WANT-NO-SPAM)
Date: 12/22/04


Date: Wed, 22 Dec 2004 07:45:11 -0500

RC wrote:
> You assume too much. Dont' think of a firewall as just INPUT. OUTPUT
> is at least as important - ie smbd. Do you follow?
>
> Of course a firewall is important but connecting to a pop3 port doesn't prove
> jack. Why run a local mail server at all, with or without a firewall? If it's running,
> it's running and will be accessible with or without a firewall. That was my point.
> That makes the telnetter's example moot.

I think we're simply misunderstanding each other and I apologize for
getting defensive.

I agree, a POP3 server is *probably* useless if it's not intended to be
exposed to the outside world. However, in the rare circumstance that aq
required a POP3 server (learning experience?), a firewall would
obviously provide another level of protection to ensure that no unwanted
visitors could read his mail.

You call the telnetter's example "moot" because the service shouldn't
have been running in the first place. Agreed, it probably shouldn't
have been running; but, it was (and maybe it was supposed to be), and aq
now walks away with a better understanding of what a firewall can
protect against. If they were only good for blocking services that
shouldn't be running, we'd never have a need for them.

-- 
Sean


Relevant Pages

  • Fedora core2 pop3
    ... I have a trusty old 7.3 box that is about retire due to age. ... spiffy new machine on which I've installed Fedora Core2. ... way to enable a pop3 server to run. ... I did not install a firewall, ...
    (linux.redhat.misc)
  • Re: Unable to connect to POP3 server on SBS2003
    ... After opening up port 110 on the router's firewall and pointing it to the IP ... Address of the SBS2003 Server, and manually starting the two POP3 services, ... Outlook was able to connect and logon to the POP3 Server. ...
    (microsoft.public.windows.server.sbs)
  • Re: POP3 proxy via ssh through server
    ... > SSH access privilege to the actual POP3 server? ... > from laptop through the firewall to my server. ...
    (comp.os.linux.networking)
  • Re: Firewall configuration (Ports)
    ... >110 inbound for pop3 ... This is because you are running a pop3 server behind the firewall, ... because you want to read your email on external pop3 servers, ...
    (comp.security.firewalls)
  • Presentation: Bypassing client application protection techniques with notepad
    ... Bypassing client application protection techniques ... Kerio Personal Firewall 4.0 ... Last years were revolutionary for network services infrastructure ...
    (NT-Bugtraq)