On Thu, Feb 19, 2004 at 11:48:50PM -0500, Archaic (archaic at wrote:
> > Netfilter can see everything dhcpd does.
> You sure about that? IIRC dhclient, unlike other clients, uses a raw
> socket. At least the last time I used it it did. iptables couldn't
> filter it because it didn't see it.

I made "no comment" in my earlier reply because dhcp is not used on any 
networks I have anything to do with (simply because there is no need). 
If the above behavior is true then I no longer see any justification for 
its use at all.

> Yeah, but spend too much time trying to minimize the number of rules
> that will match each packet and I would fear something getting missed.

Deny all by default.

After that there is no fear.  Fear (an emotion) has no place in firewall 
(or security in general) design.  If you miss something it will be 
immediately obvious because something will not work.

