Bug 147263

Summary: SuSEfirewall2: add FW_REJECT_INT="yes"
Product: [openSUSE] SUSE Linux 10.1 Reporter: Johannes Meixner <jsmeix>
Component: SecurityAssignee: Ludwig Nussel <lnussel>
Status: RESOLVED FIXED QA Contact: E-mail List <qa-bugs>
Severity: Enhancement    
Priority: P5 - None CC: lnussel
Version: Beta 2   
Target Milestone: ---   
Hardware: Other   
OS: Linux   
Whiteboard:
Found By: Development Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Comment 1 Ludwig Nussel 2006-02-01 15:16:06 UTC
jo
Comment 2 Ludwig Nussel 2006-09-20 12:01:34 UTC
done
Comment 3 Johannes Meixner 2006-09-20 12:34:25 UTC
It seems the default for the INT zone is still "drop"
(because in SuSEfirewall2.sysconfig there is only FW_REJECT="").

Is it insecure to "reject" by default for the INT zone?
Comment 4 Ludwig Nussel 2006-09-20 12:58:22 UTC
Ah, somehow overlooked that you are stressing the default case. I changed that now. The new setting also affects the forward chain, let's see if we get complaints about masquerading.