tech-net archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: Proposed Improvements to NPF



Rhialto <rhialto%falu.nl@localhost> writes:

> On Sat 07 Jun 2025 at 06:52:55 -0400, Greg Troxel wrote:
>> Josh Moyer <JMoyer%nodomain.net@localhost> writes:
>> 
>> > 3: DNS hostname lookup support.  (Is this a bad idea from a remote
>> > firewall rule manipulation attack type of perspective?)
>> 
>> (I agree with Edgar's chicken/egg comment.)
>
> Maybe Josh doesn't literally mean DNS lookup but just name lookup in
> general. That can also work with /etc/hosts or whatever else in
> /etc/nsswitch.conf that doesn't need to access the network before it has
> been set up.

Maybe, but to me the point is to accomodate a known host at a new
address.   We'll see what Josh says....


Home | Main Index | Thread Index | Old Index