|
From: Friedrich L. <fl...@fl...> - 2003-05-30 21:47:40
|
Bruce Smith wrote:
>>Add a comment to insert ones own rules _above_ the logging rules
>>and leave some more free lines in the script there so users really
>>see it.
>=20
> I figured if someone was knowledgeable enough to add their own rules,
> they would know where to add them. Depending on what they want to do,
> they may need to add rules in other places too. =20
>=20
> Is that really necessary?
If we are preparing a script for beginners....
>>># Log invalid packets from DROP policy:
>>>if [ -n "$LOGGING" ] ; then
>>> ${IPTABLES} -A INPUT -d 255.255.255.255 -j DROP # do not log broad=
casts
>>> ${IPTABLES} -A INPUT -d 224.0.0.0/8 -j DROP # do not log Microsoft=
multicasts
>>
>>Why don't you just do the above always? Do just logging when we want
>>logging.
>=20
>=20
> Efficiency. The only good these rules do is keep a bunch of extra crap
> out of the logs, so they do absolutely no good unless we're logging.=20
> The packets are dropped anyway, along with everything else, the very
> next thing because we are at the end of the chain (policy =3D drop). =20
>=20
> Why add the overhead of more rules when they don't do any good?
If someone manages to install rules after the logging rules those
rules might interfere.
Have you got something like the expresssion
DAU =3D d=FCmmster anzunehmender User
~ the most stupid user to expect
That's what I always have in mind if you do wounder about my remarks -
which sound so obvious to you that you think it's not important.
--=20
MfG / Regards
Friedrich Lobenstock
____________________________________________________________________
Friedrich Lobenstock Linux Services Lobenstock
URL: http://www.lsl.at/ Email: fl...@fl...
____________________________________________________________________
|