by deadcode » Thu Jun 26, 2008 4:43 pm
yes, whitelist is very useful. What I would like to mention is that, instead of the assigning trusted IP to the whitelist, it would be very useful for accepting trusted domain name for the whitelist as well. For home user like us, our IP is always dynamically assigned by ISP. We home user always rely on DDNS to resolve our latest IP address because ISP keep renewing our IP periodically.
I currently running 101j and 207+ in two different location, both location does not have a fix IP. If a whitelist accepts trusted domain name, then I can ensure both FTP server on 101j and 207+ only accept FTP connection between these two location by assigning DDNS domain name of these two location in the whitelist. This can greatly increase security for we home user.
//ds207+ with mod - openvpn, openldap, freeradius, squid, bind, lighttpd-webdav, nylon
//ds101j with mod - openvpn, postfix