Enabling the Network Ingress/Egress Controls

Jan 22, 2010 17:35

There have been quite a few questions lately about how to enable the SELinux network ingress/egress controls on recent Fedora releases. This is good because it means people actually want to use this stuff, but it is also bad because it tells me that I haven't done a very good job explaining how to use them. Actually, looking back on this site I ( Read more... )

userspace, selinux, netlabel, documentation

Leave a comment

Comments 2

anonymous December 12 2012, 22:49:25 UTC
Hello,

I am trying to set up a MLS system and label a node on the network, to limit what data can be sent to this node. I have set up the node label using "semanage node..." but traffic is still getting through. Are these Ingress/Egress controls something I need to set up in order to SELinux to actually block the traffic?

Reply

paulmoore December 14 2012, 19:43:23 UTC
Yes, unless you setup some sort of network labeling the network interface/node access control points will not take effect as there are no network labels to use for controlling access.

Reply


Leave a comment

Up