3 ms·
IRL, we are unable to force systemd NOT to use any network ports for security reason due to absence of Linux firewall ability to deal with this process ID on in
by egberts 6y ago
IRL, we are unable to force systemd NOT to use any network ports for security reason due to absence of Linux firewall ability to deal with this process ID on inbound packets.
Hence, OpenRC enters the picture instead just to ensure that network port is not being used.
Also, premise of the DEFAULT-DENY firewall modeling is to pinhole open the port(s) on a per-process (or per-parent-process group) basis.