[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

Re: [tor-relays] does it make sense to close unused ports at a tor relay with iptables ?



> On 28 Apr 2016, at 19:18, Toralf FÃrster <toralf.foerster@xxxxxx> wrote:
> 
> Signed PGP part
> On 04/28/2016 11:14 AM, Tim Wilson-Brown - teor wrote:
> > Ports in, or ports out?
> Ports in I meant, sry.
> 
> > Closing inbound ports is a security precaution
> The question is - if there's no program listening on that port, does filtering that in-port has any effect ?

Normally, when there is a connection attempt to a closed port, your OS will reply and let the other end know the port is closed.
With iptables, you can blackhole (drop) these requests instead.
Or you can log them.

Tim

Tim Wilson-Brown (teor)

teor2345 at gmail dot com
PGP 968F094B
ricochet:ekmygaiu4rzgsk6n



Attachment: signature.asc
Description: Message signed with OpenPGP using GPGMail

_______________________________________________
tor-relays mailing list
tor-relays@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays