"Workstation" Product defaults to wide-open firewall

Igor Gnatenko i.gnatenko.brain at gmail.com
Mon Dec 8 08:01:26 UTC 2014


On Mon, Dec 8, 2014 at 10:58 AM, Andre Robatino
<robatino at fedoraproject.org> wrote:
>
> Kevin Kofler <kevin.kofler <at> chello.at> writes:
>
> > I just happened to look at the firewalld default settings, and I was not
> > amused when I noticed this:
> > http://pkgs.fedoraproject.org/cgit/firewalld.git/tree/FedoraWorkstation.xml
> > >  <port protocol="udp" port="1025-65535"/>
> > >  <port protocol="tcp" port="1025-65535"/>
> > This "firewall" is a joke! ALL higher ports are wide open!
>
> I just did a check of all the service ports and various higher port ranges
> using ShieldsUP! ( https://www.grc.com/x/ne.dll?bh0bkyd2 ) and AFAICT, the
> only open higher port is the one random port that Transmission is currently
> using. (BTW, Transmission now seems to automatically open an incoming port -
> in F20 and below I had to tell Transmission to use a fixed port instead of a
> random one, and manually open that port in the firewall.) This is on a
> system clean installed from Fedora-Live-Workstation-x86_64-21-5.iso.
you forget about DLNA sharing, and some more GNOME services.
>
>
> --
> devel mailing list
> devel at lists.fedoraproject.org
> https://admin.fedoraproject.org/mailman/listinfo/devel
> Fedora Code of Conduct: http://fedoraproject.org/code-of-conduct




-- 
-Igor Gnatenko


More information about the devel mailing list