New Zealand ADSL Mailing List


Pinholing by protocol number

From: Glenn Phillips <glennp_at_null.net.nz>
Date: Fri, 6 Oct 2000 08:56:26 +1300 (NZDT)
Message-ID: <Pine.LNX.4.21.0010060849240.20866-100000@dev.null.net.nz>

Since I just want to forward everything to a single internal firewall,
I thought that rather than use the M10 rules, I could easily just pinhole
by number - this would get around having to have three rules just for TCP,
etc.

eg The rule:

Name = whatever
Protocol = Other
Protocol Number = 6
Destination = my.firewall.ip

Would forward all TCP traffic, with no holes for your HTTP or telnet
interfaces.

Anyone tried this?

-- 
Glenn Phillips                   glennp@null.net.nz
Technology Addict                Auckland, NZ
Categorizing telnet as a "security risk" is not unlike
referring to Ayers Rock as "big." - Stephan Somogyi 
This message is part of the NZ Broadband mailing list.
see http://unixathome.org/adsl/ for archives, FAQ,
and various documents.
To unsubscribe: send mail to majordomo@unixathome.org
with "unsubscribe adsl" in the body of the message
Received on Fri Oct 6 08:57:11 2000

This archive was generated by hypermail 2.2.0 : Thu Nov 30 11:48:06 2006 EST