Re: IPF/IPTable/??

From: Brad Arlt (arlt@cpsc.ucalgary.ca)
Date: 11/28/02

  • Next message: nee cee: "Re: Blocking personal email"
    Date: Thu, 28 Nov 2002 15:40:29 -0700
    From: Brad Arlt <arlt@cpsc.ucalgary.ca>
    To: "ALBEE,RUSSELL. S FC2 (CV63 CS5)" <ALBEER@kitty-hawk.navy.mil>
    
    

    On Thu, Nov 28, 2002 at 06:02:42AM +0900, ALBEE,RUSSELL. S FC2 (CV63 CS5) wrote:
    > Which *NIX firewall software is the best to use in terms of sercurity and
    > reliability? IPF? IPChains? IPTables?

    I consider Chains, Table, and Filter en par for stability.

    Chains might be a little more stable, but how many 9s does one really
    need? Chains doesn't protect your network as well as Tables, so while
    IPChains might keep your firewall running longer. It might not keep
    your network running longer, which is after all what your firewall is
    supposed to do.

    If you really mean "IPF" (circa Linux 2.0 kernel), and not IP Filters,
    doen't use it.

    The speed, flexablity, and statefulness of IP Tables (netfilter), make
    it the best choice.

    If you don't know what I am talking about when I say a 9, then you
    want IPTables. And you want to read more about all three so you can
    an informed decision on the merits of each, rather than the
    preferences of the masses.
    -----------------------------------------------------------------------
       __o Bradley Arlt Security Team Lead
     _ \<_ arlt@cpsc.ucalgary.ca University Of Calgary
    (_)/(_) I should be biking right now. Computer Science



    Relevant Pages

    • Re: Konvertierung ipchains -> iptables
      ... >> Firewall umsetzen muss, ist das leider nicht so einfach. ... > Die Kunden werden Dir kaum opaque ipchains-Zeilen geliefert haben, ... > iptables am besten stateful neu, wonach man schon mal halb so viele Regeln ... >> Die Umstellung von ipchains auf iptables hat rein technische Gruende. ...
      (de.comp.os.unix.networking.misc)
    • Re: Firewall software.
      ... Most modern Linux systems come with firewall installed with reasonable ... bridge or something that selectively lets packets through it. ... ipchains has been largely replaced by iptables. ...
      (comp.os.linux.networking)
    • Re: Firewall software.
      ... Most modern Linux systems come with firewall installed with reasonable ... bridge or something that selectively lets packets through it. ... ipchains has been largely replaced by iptables. ...
      (comp.os.linux.setup)
    • Re: Firewall software.
      ... Install a firewall. ... ipchains has been largely replaced by iptables. ... binary and name of the program along with the protocol and port allowed. ...
      (comp.os.linux.setup)
    • Re: iptables logging
      ... > I've just switched over to iptables from ipchains. ... > I got the new Linux firewall book by Ziegler. ... iptables uses the DROP target not DENY, and you cant have two targets ...
      (comp.os.linux.security)