Old 11-09-2011, 07:51 AM   #11 (permalink)
Untangle Ninja
 
dbunyard's Avatar
 
Join Date: Nov 2008
Location: Westerville, Ohio, USA
Posts: 1,020
dbunyard is on a distinguished road
Default

Quote:
Originally Posted by choeschen View Post
Would't the simple solution be to have UT changed the default action on iptables to block and clear out all rules on startup and shutdown? When UT is done booting it can reset the rules and default action back to how it should be. I have built my own home grown firewalls before using iptables so I know this can be done via a simple script. It does not take that much time to add a bunch of rules to iptables via a script either. I was able to run through hundreds of rules being added to iptables in a matter of seconds and that was on much older hardware then the minimum requirements UT needs.

Just my
That's kinda what I was thinking. I didn't think it would be all that hard to ensure that Untangle blocks all traffic during startup/shutdown until the system is ready for it. It's not a huge deal like I said in my post but it would still be possible for a virus or something malicious to slip through before all the rack modules are brought up.
__________________
Dan

You may one day find something interesting here. Today is not that day. Tomorrow isn't looking too good either.
dbunyard is offline  
Old 11-09-2011, 10:46 AM   #12 (permalink)
Untangle Ninja
 
sky-knight's Avatar
 
Join Date: Apr 2008
Location: Phoenix, AZ
URLs submitted: 8
Posts: 15,454
sky-knight is on a distinguished road
Default

As I said, this issue has come up in the past. I'm pretty sure that if such a thing was easy, UT would have done it by now. There are likely edge cases they ran into in testing that dictating leaving it fail open.
__________________
Rob Sandling, BS:SWE, MCP
Intouch Technology
Phone: 480-272-9889
rob@intouchtechllc.com

UntangleAppliances.com
Phone: 866-794-8879
sky-knight is offline  
Old 11-09-2011, 12:26 PM   #13 (permalink)
Untangle Ninja
 
mrunkel's Avatar
 
Join Date: Jul 2008
Posts: 2,766
mrunkel is on a distinguished road
Default

And then we have the other 3000 untangle users complaining that it blocks network traffic when the UVM shuts down.

Maybe I can see adding an option, but my first reaction is seriously? It's a window of under 30 seconds. You can use these events as a tool to show management how much spam the Untangle blocks in normal operation.
__________________
m.


Big Frickin Disclaimer:
While I'm pretty sure, I can't guarantee that I know what I'm doing. There might be a better way to do this, and this way might actually suck. Make sure you understand the implications of what you're doing before trying to follow these directions.

It often helps troubleshooting if you have a good network map. Look here if you want my advice on how to draw one.
Attention: Support and help on the Untangle Forums is provided by volunteers and community members like yourself.
If you need Untangle support please call or email support@untangle.com
mrunkel is online now  
Old 11-09-2011, 01:30 PM   #14 (permalink)
Untangle Ninja
 
sky-knight's Avatar
 
Join Date: Apr 2008
Location: Phoenix, AZ
URLs submitted: 8
Posts: 15,454
sky-knight is on a distinguished road
Default

And when you can close the window yourself with a carefully crafted packet filter rule, Untangle provides the tools for admins that don't want that opening present during a reboot to control things as they want.

So we're arguing default behavior, and since it's adjustable behavior, I call it fixed.
__________________
Rob Sandling, BS:SWE, MCP
Intouch Technology
Phone: 480-272-9889
rob@intouchtechllc.com

UntangleAppliances.com
Phone: 866-794-8879
sky-knight is offline  
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 05:34 AM.


© 2010 Untangle, Inc. All Rights Reserved.   SEO by vBSEO 3.6.0 PL2