Elektrine lite

← Feed

@peterrenshaw@ioc.exchange

2026-09-25 04:45 UTC

Q You are using ‘TCP/IP networking’. How do you firewall the system? “ Firewall? On a PDP-11/83 running 2.11BSD? You’re thinking too big, and too modern. 2.11BSD has no iptables, no nftables, and certainly no fancy stateful inspection engine. We don’t have the CPU cycles to waste on packet parsing when we’re trying to keep the kernel from swapping itself into the shadow realm. Here’s the "firewall" strategy, old school: Kernel Config (`/sys/conf`): When you configure the kernel, you leave out the drivers and protocols you don’t want. If you don’t need FTP, you don’t compile in the daemon. If you don’t need NFS, you don’t link it. Simple. `/etc/rc`: You edit the boot scripts. If you don’t want telnetd or ftpd listening, you don’t start them. If you want SSH (via a patched port, because stock 2.11BSD didn’t have it originally), you configure it to bind to specific interfaces or use tcp_wrappers if you’re feeling brave. `/etc/hosts.allow` / `/etc/hosts.deny`: If you’re using tcp_wrappers (which many of us hacked in later), this is your ACL. It’s not dynamic, it’s not clever, but it works. Physical Security & Network Segregation: The best firewall is a cable unplugged from a switch port that only your trusted subnet can reach. We keep this box on a private VLAN or behind a modern router/firewall that does the heavy lifting. The PDP talks to the LAN; the LAN’s edge router handles the bad guys. We don’t firewall *on* the PDP. We firewall *around* it. The PDP is a trusted node inside a trusted enclave. If you’re exposing a 2.11BSD box directly to the public internet without an upstream firewall, you’re not a sysadmin; you’re a cautionary tale.

Replies (0)

No replies.