On Wednesday 27 December 2000 21:53, you wrote:

> After setting up ipchains with pmfirewall's script, also find portsentry
> and have that loaded. Works fine against port-attacks. Then you should be
> reasonably safe.

Thanks for your reply. I'm interested that you run portsentry as well as 
PMfirewall. In a situation where you've blocked all access to your network 
from external hosts (as I have), would running portsentry be redundant? I'm 
trying to decide whether I should add portsentry or not.

The way I understand it, portsentry senses a port scan and then immediately 
creates a rule that adds the scanning host to a REJECT or DENY rule. So if 
you've told your firewall to do this by default for all external hosts, is 
that the same thing?

Thanks.

M.

-- 
Michael O'Henly
TENZO Design

Reply via email to