Firewall without network Stack

From: Kyle Wheeler (memoryhole@cheerful.com)
Date: 09/29/01


Message-Id: <200109290053.f8T0rGOh350225@oak.cats.ohiou.edu>
Date: Fri, 28 Sep 2001 20:53:16 -0400
From: Kyle Wheeler <memoryhole@cheerful.com>
To: Focus on Linux Mailing List <FOCUS-LINUX@SECURITYFOCUS.COM>
Subject: Firewall without network Stack

I've seen, somewhere, a project that was making a "shadow firewall" - a
Linux box that just dumped everything from the network card to a
user-land application (the kernel didn't have a network stack compiled)
and let that handle filtering and routing packets. I'm trying to find it
again...

Has anyone seen anything like this?

If not... any suggestions for places to look to begin hacking the kernel
to make my own?

~Kyle Wheeler

--
If you tell the truth, you don't have to remember what you said.
-- Mark Twain



Relevant Pages

  • Re: Firewall without network Stack
    ... Subject: Firewall without network Stack ... > Linux box that just dumped everything from the network card to a ... > user-land application (the kernel didn't have a network stack compiled) ...
    (Focus-Linux)
  • Re: Firewall without network Stack
    ... Subject: Firewall without network Stack ... > user-land application (the kernel didn't have a network stack compiled) ... it's been too long since I played with the linux kernel... ...
    (Focus-Linux)
  • Re: Network stack cloning / virtualization patches
    ... existing applications as yours appears to be. ... > against 4.8-RELEASE kernel that provide support for network stack ... > the system has to be associated with a virtual image, ...
    (freebsd-net)
  • Re: Network stack cloning / virtualization patches
    ... existing applications as yours appears to be. ... > against 4.8-RELEASE kernel that provide support for network stack ... > the system has to be associated with a virtual image, ...
    (freebsd-hackers)
  • question about MPSAFE network stack disabled
    ... MPSAFE network stack disabled, expect reduced performance. ... I do not use ipv6 nor ipsec, and they are disabled in my kernel config. ...
    (freebsd-net)