Date: Mon, 01 Jan 2001 07:52:04 -0700 From: Wes Peters <wes@softweyr.com> To: "Louis A. Mamakos" <louie@TransSys.COM> Cc: Gerhard Sittig <Gerhard.Sittig@gmx.net>, freebsd-current@FreeBSD.ORG Subject: Re: IGMP queries Message-ID: <3A509994.D341766A@softweyr.com> References: <001f01c07286$9a055a00$0e00a8c0@neland.dk> <20001230215241.M253@speedy.gsinet> <200012311049.eBVAnBr23486@whizzo.transsys.com> <20001231215515.Q253@speedy.gsinet> <200101010546.f015k9r27506@whizzo.transsys.com>
next in thread | previous in thread | raw e-mail | index | archive | help
"Louis A. Mamakos" wrote: > > EGP hasn't been in wide use for probably 7 or 8 years now. > > I think the real problem with this dynamic link issue and keeping the > connection up is that the default policy is wrong. You ought to > specify what sort of traffic is "important" and should cause a > dynamic link to be established (and kept up), rather than trying > to exclude things. > > For example, you'd probably not want to have NTP establish or keep > your link up; perhaps not DNS, either. Probabably you'd want > TCP/SSH or TCP/HTTPD though. Most SSH and HTTP traffic is preceeded by a DNS lookup; if you don't allow the DNS traffic, the SSH or HTTP traffic will never occur. Trying to predict how these things happen is a non-obvious exercise that requires careful study or you will break things horribly. We tune our default firewall configuration by practicing on our real, live internet connection at work, just to make sure we're not cutting off our customers heads. It can be quite irritating at times, but fits with the "eat your own dog food" philosophy. -- Where am I, and what am I doing in this handbasket? Wes Peters wes@softweyr.com To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-current" in the body of the message
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?3A509994.D341766A>