|
From: Bruce S. <bw...@ar...> - 2003-05-30 21:37:16
|
> > I just uploaded my latest firewall script at: > > > > http://cvs.sourceforge.net/cgi-bin/viewcvs.cgi/devil-linux/build/config/etc/init.d/firewall.rules.2nic?rev=HEAD > > Add a comment to insert ones own rules _above_ the logging rules > and leave some more free lines in the script there so users really > see it. I figured if someone was knowledgeable enough to add their own rules, they would know where to add them. Depending on what they want to do, they may need to add rules in other places too. Is that really necessary? > > # Log invalid packets from DROP policy: > > if [ -n "$LOGGING" ] ; then > > ${IPTABLES} -A INPUT -d 255.255.255.255 -j DROP # do not log broadcasts > > ${IPTABLES} -A INPUT -d 224.0.0.0/8 -j DROP # do not log Microsoft multicasts > > Why don't you just do the above always? Do just logging when we want > logging. Efficiency. The only good these rules do is keep a bunch of extra crap out of the logs, so they do absolutely no good unless we're logging. The packets are dropped anyway, along with everything else, the very next thing because we are at the end of the chain (policy = drop). Why add the overhead of more rules when they don't do any good? > > ${IPTABLES} -A INPUT -m limit --limit 3/minute --limit-burst 3 -j LOG --log-prefix "INPUT policy: " > > ${IPTABLES} -A OUTPUT -m limit --limit 3/minute --limit-burst 3 -j LOG --log-prefix "OUTPUT policy: " > > ${IPTABLES} -A FORWARD -m limit --limit 3/minute --limit-burst 3 -j LOG --log-prefix "FORWARD policy: " > > fi > > Logging are long enough, maybe just shorten the logging prefix to > "FW-IN: ", "FW-OUT: " and "FW-FWD: ". Just my own preference YMMV. Yeah, I could shorten that up some how. - BS |