From mboxrd@z Thu Jan  1 00:00:00 1970
Received: from lists.gentoo.org ([140.105.134.102] helo=robin.gentoo.org)
	by nuthatch.gentoo.org with esmtp (Exim 4.62)
	(envelope-from <gentoo-user+bounces-60536-garchives=archives.gentoo.org@gentoo.org>)
	id 1HLTpQ-0007oD-0V
	for garchives@archives.gentoo.org; Mon, 26 Feb 2007 00:34:56 +0000
Received: from robin.gentoo.org (localhost [127.0.0.1])
	by robin.gentoo.org (8.14.0/8.14.0) with SMTP id l1Q0XJEI012781;
	Mon, 26 Feb 2007 00:33:19 GMT
Received: from wr-out-0506.google.com (wr-out-0506.google.com [64.233.184.236])
	by robin.gentoo.org (8.14.0/8.14.0) with ESMTP id l1Q0Sli8007986
	for <gentoo-user@lists.gentoo.org>; Mon, 26 Feb 2007 00:28:48 GMT
Received: by wr-out-0506.google.com with SMTP id 68so1224409wri
        for <gentoo-user@lists.gentoo.org>; Sun, 25 Feb 2007 16:28:47 -0800 (PST)
DKIM-Signature: a=rsa-sha1; c=relaxed/relaxed;
        d=gmail.com; s=beta;
        h=domainkey-signature:received:received:message-id:date:from:to:subject:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references;
        b=GMJ7lMUnRuOiCJiSiJQuLDHeoPkvvz1JZZq4LTzDVlG97JouUhavSh7kBEPJmrSuiqxmt8ZM6MjzfkQuObM+RM+4n19JXTJclOadKY0kG/edWzARy8VRrvLQYTzxW4GX+zAp8NEH47zoKGxJkoJ26BWLrYY6zhi25T1su3RUHV0=
DomainKey-Signature: a=rsa-sha1; c=nofws;
        d=gmail.com; s=beta;
        h=received:message-id:date:from:to:subject:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references;
        b=oIdSGhE5TpUZQVZ4C/HNEcrNeMKUJUas1vrNQxsJpIZAslUriQjhuxpyy+wNLa32Iq9meeqR6uDpQ3ixq9n7ZZY+8f//5Ksbs83KlLK1+tjdWlDHPEDmccmHXppS99gYiHKSVBK+oDBi+chqxUaJxncewwPKvSz885p4Wp/Z0K8=
Received: by 10.114.39.16 with SMTP id m16mr1126354wam.1172449727001;
        Sun, 25 Feb 2007 16:28:47 -0800 (PST)
Received: by 10.114.176.15 with HTTP; Sun, 25 Feb 2007 16:28:46 -0800 (PST)
Message-ID: <49bf44f10702251628k6f9261eepaeba900d7751aa9f@mail.gmail.com>
Date: Sun, 25 Feb 2007 16:28:46 -0800
From: Grant <emailgrant@gmail.com>
To: gentoo-user@lists.gentoo.org
Subject: Re: [gentoo-user] What if the firewall doesn't start?
In-Reply-To: <200702252247.43130.michaelkintzios@gmail.com>
Precedence: bulk
List-Post: <mailto:gentoo-user@lists.gentoo.org>
List-Help: <mailto:gentoo-user+help@gentoo.org>
List-Unsubscribe: <mailto:gentoo-user+unsubscribe@gentoo.org>
List-Subscribe: <mailto:gentoo-user+subscribe@gentoo.org>
List-Id: Gentoo Linux mail <gentoo-user.gentoo.org>
X-BeenThere: gentoo-user@gentoo.org
Reply-to: gentoo-user@lists.gentoo.org
MIME-Version: 1.0
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
References: <49bf44f10702251158n2ab9c587y9563d6ad4fa3a4b3@mail.gmail.com>
	 <200702252247.43130.michaelkintzios@gmail.com>
X-Archives-Salt: 12f839e5-2f25-4452-b79c-6b5476c6b3db
X-Archives-Hash: 4f54b2bdbd8f5d55d5af6ef04175ef97

> > It occurred to me that if the shorewall firewall on my headless router
> > doesn't start for whatever reason, I'll be totally exposed.  Is there
> > a way to protect against that?
>
> Well, you'll get an error during boot that iptables did not come up.

The machine is headless though.

> I assume that shorewall is only run when you change the script and
> otherwise /etc/init.d/iptables is run as a default service after boot.

Ouch.  No.  I'm running shorewall in the default runlevel and iptables
explicitly not at all.  I thought running shorewall was all I needed
to do.  Can you confirm that I should be running iptables in the
default runlevel and shorewall only when I want to update the config?

> Anyway, a closed port remains closed whether a firewall is running, or not.

I thought the firewall specified which ports to open/close.

- Gramt
-- 
gentoo-user@gentoo.org mailing list