5.3-RELEASE kde 3.3 and pf

Michael Butler imbutler at comcast.net
Wed Nov 10 06:22:47 PST 2004


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

> Maybe you should allow everything on lo0, in and out.

127/8 should always be allowed on the loopback interface,
127/8 should always be dropped from all other interfaces.

I am "uncomfortable" saying that everything should be allowed ..

Michael Butler CISSP
Security Consultant
Savvis Communications
www.savvis.net
PGP Key ID: 0x5E873CC5


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.6 (FreeBSD)

iD8DBQFBkiQviJykeV6HPMURAuGvAKCxPvD2JBnymAZi6DSGv+h39whQoQCfSp+x
TmQ7x0bqDw49rGjemk8WQUg=
=Y6/E
-----END PGP SIGNATURE-----



More information about the freebsd-stable mailing list