Slashdot Mirror


Run Your Firewall Halted for Extra Security

n8willis writes: "There's a great article over at the SysAdmin magazine site that presents a unique approach to improving network security: run your firewall in a halted state. This means runlevel 0; no processes running and no disks mounted, but with packet filtering still on. The author heard a rumor of this capability in the 2.0 series kernels, and he's managed to get it working in 2.2 as well."

9 of 390 comments (clear)

  1. Works for me... by Rorschach1 · · Score: 4, Funny

    Though I usually just use the power switch. Can't beat a powered-off firewall for security.

    1. Re:Works for me... by Jonny+Ringo · · Score: 2, Funny

      I actually just light mine on fire. It just makes sense, than once the fire catches to the cords I know I'm secure.

  2. better still.. by Hooya · · Score: 2, Funny

    is the system i have at home. i look at each incoming packet on paper and then pass it on the the lan if it looks legit. the only way to punch a hole in the firewall is with a shotgun at my belly..

  3. Old news by pHalec · · Score: 2, Funny

    Bah, I've got an old Pentium with some faulty memory that crashes on a regular basis.

    It's been reliably packet-forwarding for me for over a month with a kernel-oops on screen.

  4. Re:Logging? - syslog by JimR · · Score: 2, Funny

    As other people have pointed out there will be no
    syslog running in runlevel 0.

    I guess you could always run the video out into
    a VCR... or use a serial console and a line printer.

    --
    #exclude <ms/windows.h>
  5. But... by Klowner · · Score: 3, Funny

    Then how would I telnet to my firewall from school?

    *dodges flying shoes*

    ;)

    Klowner

  6. I'm more secure by Anonymous Coward · · Score: 2, Funny

    Cool! I just halted my BlackIce service. If I hadn't read this article, I would never have known that doing that would make me more secure.

    Thanks Slashdot :) You rock. I don't have to worry about my hard drive shares being exposed now...

  7. Re:Logging? by Foxman98 · · Score: 3, Funny

    would be fairly easy...

    see we have this thing these days....

    it's called "fire"

    i have portable "fire creation device".

    commonly called a "lighter"

    ;-p

    --
    S.t.e.v.e.
  8. Can't use it, either. by mfh · · Score: 2, Funny

    Just testing my user id #56 really. :)

    --
    The dangers of knowledge trigger emotional distress in human beings.