From owner-freebsd-questions@FreeBSD.ORG Sun Apr 2 16:52:19 2006 Return-Path: X-Original-To: questions@freebsd.org Delivered-To: freebsd-questions@FreeBSD.ORG Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 8D6BB16A400 for ; Sun, 2 Apr 2006 16:52:19 +0000 (UTC) (envelope-from norgaard@locolomo.org) Received: from strange.daemonsecurity.com (59.Red-81-33-11.staticIP.rima-tde.net [81.33.11.59]) by mx1.FreeBSD.org (Postfix) with ESMTP id 197BD43D53 for ; Sun, 2 Apr 2006 16:52:18 +0000 (GMT) (envelope-from norgaard@locolomo.org) Received: from [172.16.2.1] (charm.daemonsecurity.com [172.16.2.1]) by strange.daemonsecurity.com (Postfix) with ESMTP id B25682E041; Sun, 2 Apr 2006 18:52:24 +0200 (CEST) Message-ID: <44300138.8030502@locolomo.org> Date: Sun, 02 Apr 2006 18:52:08 +0200 From: =?ISO-8859-1?Q?Erik_N=F8rgaard?= Organization: Locolomo.ORG User-Agent: Thunderbird 1.5 (X11/20060312) MIME-Version: 1.0 To: Niklaus References: <85e0e3140604020746t19565d1doc61493b89ec87905@mail.gmail.com> In-Reply-To: <85e0e3140604020746t19565d1doc61493b89ec87905@mail.gmail.com> Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Cc: questions@freebsd.org Subject: Re: disable listen on ports X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 02 Apr 2006 16:52:19 -0000 Niklaus wrote: > Hi, > How do i disable users on a system to run their own http proxy. I > don't want to allow users who have login accounts on my system to > listen to any port . How do i do that. Putting up a packet filter as some suggest may break other things. Instead, you can take a look at MAC, Mandatory Access Controls. There is a module mac_portacl(4) that can control this. You need to compile your kernel with options MAC and then add mac_portacl_load="YES" to loader.conf But don't ask me how it works, haven't used it. Cheers, Erik -- Ph: +34.666334818 web: www.locolomo.org S/MIME Certificate: www.daemonsecurity.com/ca/8D03551FFCE04F06.crt Subject ID: 9E:AA:18:E6:94:7A:91:44:0A:E4:DD:87:73:7F:4E:82:E7:08:9C:72 Fingerprint: 5B:D5:1E:3E:47:E7:EC:1C:4C:C8:3A:19:CC:AE:14:F5:DF:18:0F:B9