tech-net archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]
Re: Proposed Improvements to NPF
Rhialto <rhialto%falu.nl@localhost> writes:
> On Sat 07 Jun 2025 at 06:52:55 -0400, Greg Troxel wrote:
>> Josh Moyer <JMoyer%nodomain.net@localhost> writes:
>>
>> > 3: DNS hostname lookup support. (Is this a bad idea from a remote
>> > firewall rule manipulation attack type of perspective?)
>>
>> (I agree with Edgar's chicken/egg comment.)
>
> Maybe Josh doesn't literally mean DNS lookup but just name lookup in
> general. That can also work with /etc/hosts or whatever else in
> /etc/nsswitch.conf that doesn't need to access the network before it has
> been set up.
Maybe, but to me the point is to accomodate a known host at a new
address. We'll see what Josh says....
Home |
Main Index |
Thread Index |
Old Index