Development issues regarding the cerowrt test router project
 help / color / mirror / Atom feed
* [Cerowrt-devel] router hardening
@ 2016-01-18 18:35 Dave Täht
  2016-01-19  9:29 ` Alan Jenkins
  0 siblings, 1 reply; 2+ messages in thread
From: Dave Täht @ 2016-01-18 18:35 UTC (permalink / raw)
  To: cerowrt-devel

One of my issues with blindly applying techniques to block certain IPs
is trusting the sources of the data - many people have ended up on a
blocklist that shouldn't have.

That said, ipset is so effective and so scalable, that perhaps deploying
this by default

http://www.linuxjournal.com/content/server-hardening?page=0,1

would be a good idea.

Are there any more ipv6 specific blocklists out there?

^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: [Cerowrt-devel] router hardening
  2016-01-18 18:35 [Cerowrt-devel] router hardening Dave Täht
@ 2016-01-19  9:29 ` Alan Jenkins
  0 siblings, 0 replies; 2+ messages in thread
From: Alan Jenkins @ 2016-01-19  9:29 UTC (permalink / raw)
  To: Dave Täht; +Cc: cerowrt-devel

On 18/01/2016, Dave Täht <dave@taht.net> wrote:
> One of my issues with blindly applying techniques to block certain IPs
> is trusting the sources of the data - many people have ended up on a
> blocklist that shouldn't have.
>
> That said, ipset is so effective and so scalable, that perhaps deploying
> this by default
>
> http://www.linuxjournal.com/content/server-hardening?page=0,1
>
> would be a good idea.
>
> Are there any more ipv6 specific blocklists out there?

Note the RBN list it links to says it's obsolete for 2 years.  (Other
Emerging Threat lists are available, as transparent aggregation of a
very small number of trusted sources.  Still useful but rather less
ambitious.  Unfortunately the documentation still describes the
obsolete lists.  Maybe somewhere else is more active).

It sounds like one needs a list to stay up to date on which blocklists
to use :).

Alan

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2016-01-19  9:29 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2016-01-18 18:35 [Cerowrt-devel] router hardening Dave Täht
2016-01-19  9:29 ` Alan Jenkins

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox