Re: iptables rule to block FTP-NAT-Helper-Traffic



Kevin Kempfer <usenet_spam@xxxxxxxxxxxxxx> wrote:

which I have in mind, but I cannot stop all users on my network to use java.

Is there a particular reason that they need to run Java applets?

Java is insecure by design IMHO.

I would just filter this out using some sort of dynamic page modifying
filtering proxy system like proximodo to remove the Java related
content, and make sure all clients can only connect to the world wide
web via this proxy.

If your users need specific Java applets, there could be a pool of
approved applets hosted locally.

Mark.

--
Mark Hobley
Linux User: #370818 http://markhobley.yi.org/

.