Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 23 Aug 2002 10:34:53 -0400
From:      Jacques Perrolle <yellow@RadOnc.Duke.EDU>
To:        questions@FreeBSD.org
Subject:   IPFW
Message-ID:  <7CDFAC86-B6A5-11D6-B3F4-003065B4FE54@radonc.duke.edu>

next in thread | raw e-mail | index | archive | help
Greetings,

Isn't it dangerous to have a firewall that allows the use of domain 
names, forcing it to resolve them with DNS?  This just begs for someone 
to DNS spoof it, rendering the firewall virtually worthless.  Also, 
apparently the rules that I create aren't static?  I encountered this 
yesterday when my main DNS was having a hiccup and the firewall rules on 
all my machines running IPFW were suddenly completely changed, replaced 
with root.register.com IP addresses.  Is there someway I've missed in 
all the docs to keep my rules in effect no matter what?

Jacques


-------------------------------------------
Jacques Perrolle		
Duke University Health System
Department of Radiation Oncology
04216 Red Zone Duke Hospital South
Office: (919) 660-2169
Pager: (919) 970-0955


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-questions" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?7CDFAC86-B6A5-11D6-B3F4-003065B4FE54>