[nzlug] Firewall ruleset check...

Peter webwiz at pl.net
Wed May 14 19:21:51 NZST 2008


The primary reason is that ive added this whole ip accounting layer, which those tools dont do.

But i have installed a couple of those packages and examined their resultant rulesets, and duly "merged" their rules into this ruleset, however adding more bits and pieces cumulatively doesnt make it better ;-)

P.





> I'd advise using something like stonewall, which, as many of these tools 
> are, is an iptables rules generator under the hood. Why re-invent the 
> wheel when you can use someone else's expertise.
> 
> Cheers,
> 
> Cliff




More information about the NZLUG mailing list