Re: iptables not logging or dhcp-client lying?

2002-04-11 Thread Olaf Meeuwissen
Olaf Meeuwissen [EMAIL PROTECTED] writes: Gabor Kovacs [EMAIL PROTECTED] writes: Olaf Meeuwissen wrote: Basically, I'd like to keep the setup as closed as possible so I make a hole in /etc/dhclient-enter-hooks during the PREINIT stage to let the DHCPDISCOVER broadcast out (and a

Re: iptables not logging or dhcp-client lying?

2002-04-11 Thread Olaf Meeuwissen
Olaf Meeuwissen [EMAIL PROTECTED] writes: Gabor Kovacs [EMAIL PROTECTED] writes: Olaf Meeuwissen wrote: Basically, I'd like to keep the setup as closed as possible so I make a hole in /etc/dhclient-enter-hooks during the PREINIT stage to let the DHCPDISCOVER broadcast out (and a

Re: iptables not logging or dhcp-client lying?

2002-04-08 Thread Olaf Meeuwissen
Gabor Kovacs [EMAIL PROTECTED] writes: Olaf Meeuwissen wrote: Basically, I'd like to keep the setup as closed as possible so I make a hole in /etc/dhclient-enter-hooks during the PREINIT stage to let the DHCPDISCOVER broadcast out (and a reply back in eventually, taking this one step

Re: iptables not logging or dhcp-client lying?

2002-04-08 Thread Olaf Meeuwissen
Gabor Kovacs [EMAIL PROTECTED] writes: Olaf Meeuwissen wrote: Basically, I'd like to keep the setup as closed as possible so I make a hole in /etc/dhclient-enter-hooks during the PREINIT stage to let the DHCPDISCOVER broadcast out (and a reply back in eventually, taking this one step

Re: iptables not logging or dhcp-client lying?

2002-04-03 Thread Lupe Christoph
On Wednesday, 2002-04-03 at 14:02:20 +0900, Olaf Meeuwissen wrote: I am playing with packet filtering on a DHCP client and trying to get it done the right way. The right way is to dispense with DHCP. The protocol has no security whatsoever. Read RFC2131, 7. Security Considerations for

Re: iptables not logging or dhcp-client lying?

2002-04-03 Thread Olaf Meeuwissen
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Lupe Christoph [EMAIL PROTECTED] writes: On Wednesday, 2002-04-03 at 14:02:20 +0900, Olaf Meeuwissen wrote: I am playing with packet filtering on a DHCP client and trying to get it done the right way. The right way is to dispense with

Re: iptables not logging or dhcp-client lying?

2002-04-03 Thread Gabor Kovacs
Olaf Meeuwissen wrote: Basically, I'd like to keep the setup as closed as possible so I make a hole in /etc/dhclient-enter-hooks during the PREINIT stage to let the DHCPDISCOVER broadcast out (and a reply back in eventually, taking this one step at a time ;-). At least, that's what I

Re: iptables not logging or dhcp-client lying?

2002-04-03 Thread Lupe Christoph
On Wednesday, 2002-04-03 at 14:02:20 +0900, Olaf Meeuwissen wrote: I am playing with packet filtering on a DHCP client and trying to get it done the right way. The right way is to dispense with DHCP. The protocol has no security whatsoever. Read RFC2131, 7. Security Considerations for details.

Re: iptables not logging or dhcp-client lying?

2002-04-03 Thread Olaf Meeuwissen
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Lupe Christoph [EMAIL PROTECTED] writes: On Wednesday, 2002-04-03 at 14:02:20 +0900, Olaf Meeuwissen wrote: I am playing with packet filtering on a DHCP client and trying to get it done the right way. The right way is to dispense with DHCP.

Re: iptables not logging or dhcp-client lying?

2002-04-03 Thread Gabor Kovacs
Olaf Meeuwissen wrote: Basically, I'd like to keep the setup as closed as possible so I make a hole in /etc/dhclient-enter-hooks during the PREINIT stage to let the DHCPDISCOVER broadcast out (and a reply back in eventually, taking this one step at a time ;-). At least, that's what I thought

iptables not logging or dhcp-client lying?

2002-04-02 Thread Olaf Meeuwissen
Dear .debs, I am playing with packet filtering on a DHCP client and trying to get it done the right way. Policy for all built-in chains is DROP and all packets are logged before they go plonk. I pulled the network cable while playing around. Debian GNU/Linux 3.0 kernel 2.4.18-tux, iptables

iptables not logging or dhcp-client lying?

2002-04-02 Thread Olaf Meeuwissen
Dear .debs, I am playing with packet filtering on a DHCP client and trying to get it done the right way. Policy for all built-in chains is DROP and all packets are logged before they go plonk. I pulled the network cable while playing around. Debian GNU/Linux 3.0 kernel 2.4.18-tux, iptables