Add Comment

You are not currently logged in. If you do not have a user account then please consider creating one and logging in before you post your comment. This will allow you to track replies to your comment, and take part in the site much more freely.

To add your comment, fill in all the boxes below and then preview it to make sure you're happy with the way that it looks.

This is the comment you were replying to, attached to the article Struggling to implement PCI compliance:


Re: Why apply firewall AFTER bringing up interface?
Posted by Steve (82.32.xx.xx) on Sat 22 Mar 2008 at 23:14

If you're like me then you might have an exception which says something like:

  • Allow all connections from foo.bar.com.

If you run that rule before networking is brought up then DNS resolution will fail .. So I accept the small risk to avoid having to use IPs not DNS.

(Again relying on DNS to be correct is also a hole, but I think it is a small risk.)

Steve


Username:Anonymous
Title:
Your Comment:

Posting Format:

 

Inappropriate comments will be removed.

Some help on entry formatting is available

User Login

Username:

Password:

[ Advanced Login ]

Register Account

Quick Site Search