<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Firewall on Damien Dye&#39;s Blog</title>
    <link>https://blogs.damiendye.uk/en/tags/firewall/</link>
    <description>Recent content in Firewall on Damien Dye&#39;s Blog</description>
    <generator>Hugo</generator>
    <language>en-GB</language>
    <lastBuildDate>Thu, 24 Sep 2026 09:00:00 +0100</lastBuildDate>
    <atom:link href="https://blogs.damiendye.uk/en/tags/firewall/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>DNS Over HTTPS Walks Straight Past Your Controls</title>
      <link>https://blogs.damiendye.uk/en/dns/dns-over-https-walks-past-your-controls/</link>
      <pubDate>Thu, 24 Sep 2026 09:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/dns/dns-over-https-walks-past-your-controls/</guid>
      <description>DoH sends your DNS lookup to a resolver of the client&amp;#39;s choosing on port 443, which your own resolver never sees, so it cannot block a bad name or log it. Sold as privacy, but DoT gave you that in 2016. What DoH really adds is bypassing the network admin. The mechanism, the malware, who pushed it, the courts now suing the resolvers, and the fix.</description>
    </item>
    <item>
      <title>Your Firewall Takes Instructions From Strangers. Turn Off the Protocol Helpers.</title>
      <link>https://blogs.damiendye.uk/en/networking/protocol-helpers-turn-them-off/</link>
      <pubDate>Mon, 14 Sep 2026 09:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/networking/protocol-helpers-turn-them-off/</guid>
      <description>A NAT helper reads the inside of your packets and opens inbound ports on what it finds there. Anyone can write that text — a web page has been enough since 2010. How helpers work, how crafted packets turn them into a port-opening service for strangers, what IPsec pass-through does, why they fail Cyber Essentials, and how to switch the lot off.</description>
    </item>
    <item>
      <title>Ping: The Diagnostic Tool That Opens a Whole Lot More</title>
      <link>https://blogs.damiendye.uk/en/networking/ping-the-diagnostic-tool-that-opens-a-whole-lot-more/</link>
      <pubDate>Tue, 01 Sep 2026 08:05:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/networking/ping-the-diagnostic-tool-that-opens-a-whole-lot-more/</guid>
      <description>Why ping — ICMP echo, not the rest of the protocol — is a liability: a channel every host must answer, so a network that &amp;#39;only allows ping&amp;#39; has a full VPN out. The threat, who can open one, three tunnels (Hans, icmptunnel, a Python one with AES-128), and the rule that shuts it: nftables, pf, Cisco, Junos, MikroTik and Windows.</description>
    </item>
    <item>
      <title>The Firewall Is Eleven Hops Away</title>
      <link>https://blogs.damiendye.uk/en/networking/how-far-away-is-the-firewall/</link>
      <pubDate>Fri, 28 Aug 2026 09:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/networking/how-far-away-is-the-firewall/</guid>
      <description>A connection that times out tells you nothing about where it died. TTL does. Here is how to count the hops to whatever is eating your port, on Linux, macOS, the BSDs, Solaris and Redox, with a script that needs no root on Linux.</description>
    </item>
  </channel>
</rss>
