Re: Syncing iptables rules between two servers



On 2006-04-09 Lars Solberg wrote:
Is there anyone that know about how I can "sync" iptables rules on two
different servers? The plan is to have (on one of the servers) a
script that automaticly block ip adresses with iptables depending on
different conditions. When that ip adress is blocked I want it to
automaticly be blocked on another server to.

Maybe you can use iptables-save, iptables-restore and rsync to achieve
this. However, IMHO automatic network shunning is a Very Bad Idea(tm),
so I'd advise strongly against this.

Regards
Ansgar Wiechers
--
"All vulnerabilities deserve a public fear period prior to patches
becoming available."
--Jason Coombs on Bugtraq

-------------------------------------------------------------------------
This List Sponsored by: Webroot

Don't leave your confidential company and customer records un-protected.
Try Webroot's Spy Sweeper Enterprise(TM) for 30 days for FREE with no
obligation. See why so many companies trust Spy Sweeper Enterprise to
eradicate spyware from their networks.
FREE 30-Day Trial of Spy Sweeper Enterprise

http://www.webroot.com/forms/enterprise_lead.php
--------------------------------------------------------------------------



Relevant Pages

  • Re: Syncing iptables rules between two servers
    ... Is there anyone that know about how I can "sync" iptables rules on two ... The plan is to have (on one of the servers) a ... See why so many companies trust Spy Sweeper Enterprise to eradicate spyware from their networks. ...
    (Security-Basics)
  • Re: Syncing iptables rules between two servers
    ... Is there anyone that know about how I can "sync" iptables rules on two ... The plan is to have (on one of the servers) a ... shell script that sets up your firewall rules, and then run it with ssh -c. ... See why so many companies trust Spy Sweeper Enterprise to eradicate spyware from their networks. ...
    (Security-Basics)
  • RE: RedHat security
    ... Larry, ... Why would you use iptables for internal servers? ... unsubscribe mailto:redhat-list-request@redhat.com?subject=unsubscribe ...
    (RedHat)
  • Re: Syncing iptables rules between two servers
    ... I'v started making a script for doing this in bash ... Syncing iptables rules between two servers ... Try Webroot's Spy Sweeper Enterprisefor 30 days for FREE with no ...
    (Security-Basics)
  • Re: Syncing iptables rules between two servers
    ... I'v started making a script for doing this in bash ... servers, sort out dublicates, sort out ips that is whitelistet (if ... Syncing iptables rules between two servers ...
    (Focus-Linux)