On 9/5/10 11:38 AM, Mr Dash Four wrote:
> 
>> I guess I'm baffled as to why a firewall needs to have an outgoing
>> blacklist.
>>   
> Simple scenario - say I use p2p-type program (like azureus or something)
> or, worse still, have a rogue code/process/program on my machine (that I
> know nothing of) which tries to communicate from my machine to IP
> addresses which are banned (i.e. try to "call home") - in that case I
> would need these packets to be dropped without question.
> 

So this isn't really a firewall -- it's a host that happens to run
Shorewall. That is not a use case that I target with Shorewall, although
Shorewall can be used there.

-Tom
-- 
Tom Eastep        \ When I die, I want to go like my Grandfather who
Shoreline,         \ died peacefully in his sleep. Not screaming like
Washington, USA     \ all of the passengers in his car
http://shorewall.net \________________________________________________

Attachment: signature.asc
Description: OpenPGP digital signature

------------------------------------------------------------------------------
This SF.net Dev2Dev email is sponsored by:

Show off your parallel programming skills.
Enter the Intel(R) Threading Challenge 2010.
http://p.sf.net/sfu/intel-thread-sfd
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to