OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: Restricting incoming connections

From: Sandy Drobic (postfix-usersjapantest.homelinux.com)
Date: Wed Jul 05 2006 - 04:36:26 CDT


Harvey Smith wrote:
> On Wed, Jul 05, 2006 at 10:10:26AM +0200, Sandy Drobic wrote:
>> Paul Tader wrote:
>>> Sorry, my fault. What I meant to post was:
>>>
>>> mynetworks = 64.18.0.0/28, 123.456.789.0/28, 10.1.10.0/24 (Postini,
>>> DMZ, private LAN).
>>>
>> The postini ip is still not in your definition of mynetworks! You
>> probably wanted to include all hosts in 64.18.x.x where x is any
>> possible ip address.
>> Use 64.18.0.0/16 in that case. Though I definitely think postini has too
>> many ip addresses, they should give some of them to poor little me!
>>
>> Please check the documentation on cidr notations.
>>
>
> Well according to whois 64.18.0.0/28 isn't not big enough an
> 64.18.0.0/16 is a tad too big.
>
> NetRange: 64.18.0.0 - 64.18.15.255
> CIDR: 64.18.0.0/20
> NetName: POSTINI-ARIN-ASSIGNMENT
>
> so I would try using 64.18.0.0/20

I was too lazy to check the range. This is something the OP should have
been told by Postini, though. (^-^)

Hm, I still think they have too many addresses...

Sandy