From owner-freebsd-current Sun Jun 30 14:41:24 1996 Return-Path: owner-current Received: (from root@localhost) by freefall.freebsd.org (8.7.5/8.7.3) id OAA19275 for current-outgoing; Sun, 30 Jun 1996 14:41:24 -0700 (PDT) Received: from mexico.brainstorm.eu.org (root@mexico.brainstorm.eu.org [193.56.58.253]) by freefall.freebsd.org (8.7.5/8.7.3) with ESMTP id OAA19267 for ; Sun, 30 Jun 1996 14:41:19 -0700 (PDT) Received: from brasil.brainstorm.eu.org (brasil.brainstorm.eu.org [193.56.58.33]) by mexico.brainstorm.eu.org (8.7.5/8.7.3) with ESMTP id XAA00987; Sun, 30 Jun 1996 23:41:13 +0200 Received: (from uucp@localhost) by brasil.brainstorm.eu.org (8.6.12/8.6.12) with UUCP id XAA11578; Sun, 30 Jun 1996 23:40:36 +0200 Received: (from roberto@localhost) by keltia.freenix.fr (8.8.Alpha.5/keltia-uucp-2.8) id XAA00568; Sun, 30 Jun 1996 23:01:57 +0200 (MET DST) From: Ollivier Robert Message-Id: <199606302101.XAA00568@keltia.freenix.fr> Subject: Re: Firewalling DNS TCP (was Re: IPFW bugs?) To: imp@village.org (Warner Losh) Date: Sun, 30 Jun 1996 23:01:57 +0200 (MET DST) Cc: freebsd-current@FreeBSD.ORG (FreeBSD Current Users' list) In-Reply-To: <199606301944.NAA00922@rover.village.org> from Warner Losh at "Jun 30, 96 01:44:44 pm" X-Operating-System: FreeBSD 2.2-CURRENT ctm#2178 X-Mailer: ELM [version 2.4ME+ PL22 (25)] MIME-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit Sender: owner-current@FreeBSD.ORG X-Loop: FreeBSD.org Precedence: bulk It seems that Warner Losh said: > comp.protocols.tcp-ip.domain) that concluded this is a *BAD* idea. If > you have any large records, they will be truncated by this and could > lead to bogus mail delivery (if the remote end doesn't properly detect > the truncated bit). It really buys you nothing unless you and all of That what I said. We are in agreement about the uselessness of filtering TCP:53. I had to fight with my boss (I was security consultant till friday) because he insisted to block it... -- Ollivier ROBERT -=- The daemon is FREE! -=- roberto@keltia.freenix.fr FreeBSD keltia.freenix.fr 2.2-CURRENT #12: Sun Jun 30 14:10:07 MET DST 1996