BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] Port Scanning
- Subject: [Discuss] Port Scanning
- From: richard.pieri at gmail.com (Rich Pieri)
- Date: Sat, 17 Aug 2024 14:44:29 -0400
- In-reply-to: <88182572-47c2-4e13-a460-55a30ea06996@borg.org>
- References: <20240801182824.4bf21319.Richard.Pieri@gmail.com> <f6d905fd-7886-4cf2-9b02-f6d89f60adf0@borg.org> <20240801214606.5bebc46a.Richard.Pieri@gmail.com> <20c3240d-184f-4c84-b4ed-7680ac5301bd@borg.org> <CAJFsZ=o7btMacs-OqTB0908ehYkZCFGtupLkNi59C9K8XV6zKQ@mail.gmail.com> <20240804112131.195b6e56.Richard.Pieri@gmail.com> <CAJFsZ=roiGszBrbv6CzFY57V=fBe9CnZKqBi-eSUQ8eTHPr8_A@mail.gmail.com> <0b343b65-a7f6-4800-9925-aa9d08a62f82@syntheticblue.com> <20240806154705.ubfekthzywobbfn5@randomstring.org> <83a6b5f4-f82c-40e9-98ad-79681e04d9f2@syntheticblue.com> <20240806170304.2bhs5pxr2v4nytj7@randomstring.org> <20240809113255.75d77661@mydesk.domain.cxm> <e9b606a1fd6e66246af4dff99981aa69.squirrel@mail.mohawksoft.com> <20240810084927.112f285f.Richard.Pieri@gmail.com> <35ef8e1d-e39d-4567-8a5f-7776bd0361b2@borg.org> <20240810152446.7bec6364.Richard.Pieri@gmail.com> <88182572-47c2-4e13-a460-55a30ea06996@borg.org>
On Sat, 17 Aug 2024 11:05:40 -0700 Kent Borg <kentborg at borg.org> wrote: > I seem to remember someone saying that firewalls don't fail "off", or > something like that. > > Well, on a Linode machine I have, running very standard Debian, with > no real customizations, I noticed today the firewall was off: That was me; and the context was border firewalls, not host or "personal" firewalls. Border firewalls do indeed fail off: if a firewall node faults, or if it is powered off or disconnected, all traffic routed through it stops. how-EV-ver... UFW is not a firewall. The firewall is the kernel Netfilter packet filter system. UFW is a simplified front end to Netfilter, replacing the iptables command for basic host firewall management. Netfilter is always "on" while the kernel is running even when no rules are applied, and therefore it cannot fail or fault per se. UFW is disabled by default on Ubuntu; YMMV with other distros which use it. This is not a failure/fault state of Netfilter: it is on; but it has not been configured with any rules. It is the operator's responsibility to enable the UFW or other firewall rules service, if desired, and to configure and test firewall rules. If you were to configure a Linux box as a border firewall then it would behave the same as any other border firewall system: if the machine fails or faults, or if the firewall rules service is not started, then no traffic will pass through. Note: on systemd-based systems, the enable keyword does not start the service immediately. You need the --now switch or two commands: systemctl enable --now ufw.service or systemctl enable ufw.service systemctl start ufw.service -- \m/ (--) \m/
- References:
- [Discuss] Port Scanning
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] Port Scanning
- From: kentborg at borg.org (Kent Borg)
- [Discuss] Port Scanning
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] Port Scanning
- From: kentborg at borg.org (Kent Borg)
- [Discuss] Port Scanning
- From: bogstad at pobox.com (Bill Bogstad)
- [Discuss] Port Scanning
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] Port Scanning
- From: bogstad at pobox.com (Bill Bogstad)
- [Discuss] Port Scanning
- From: daniel at syntheticblue.com (Daniel M Gessel)
- [Discuss] Port Scanning
- From: dsr at randomstring.org (Dan Ritter)
- [Discuss] Port Scanning
- From: daniel at syntheticblue.com (Daniel M Gessel)
- [Discuss] Port Scanning
- From: dsr at randomstring.org (Dan Ritter)
- [Discuss] Port Scanning
- From: slitt at troubleshooters.com (Steve Litt)
- [Discuss] Port Scanning
- From: markw at mohawksoft.com (markw at mohawksoft.com)
- [Discuss] Port Scanning
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] Port Scanning
- From: kentborg at borg.org (Kent Borg)
- [Discuss] Port Scanning
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] Port Scanning
- From: kentborg at borg.org (Kent Borg)
- [Discuss] Port Scanning
- Prev by Date: [Discuss] Port Scanning
- Next by Date: [Discuss] Email failure notices from blu.org?
- Previous by thread: [Discuss] Port Scanning
- Next by thread: [Discuss] Port Scanning
- Index(es):