Re: iptables vs ipchains?

From: Cedric Blancher (blancher_at_cartel-securite.fr)
Date: 08/08/03


Date: Fri, 08 Aug 2003 08:05:13 +0200

Dans sa prose, kj nous ecrivait :
> I currently run iptables in a 2.4.21 kernel, but I have to go back to
> 2.2.25 kernel for some issues.
> The box sits on the internet, with only http and ssh open, having the rest
> of my system on ipmasq/NAT behind it.
> Is running ipchains safe enough?

Yes it is.

You will lose stateful filtering, but there's no critical loss when you
only filter simple local services like HTTP or SSH. FTP filtering would
have raised an issue, but as you do not provide it, it's OK.

For ipmasq, no problem as well. When you say ipmasq/NAT, do you mean
there's port redirection from public IP to LAN ?

-- 
BOFH excuse #378:
Operators killed by year 2000 bug bite.


Relevant Pages

  • Re: [PATCH 4/6 v2] HID: magicmouse: remove axis data filtering
    ... filtering for type A devices) before and after this change would be reassuring. ... For type A devices, the filtering is performed in userspace, in mtdev, in the ... same manner as it would have been performed in the kernel in the MT slot case. ...
    (Linux-Kernel)
  • Re: [PATCH 4/6 v2] HID: magicmouse: remove axis data filtering
    ... filtering for type A devices) before and after this change would be reassuring. ... For type A devices, the filtering is performed in userspace, in mtdev, in the ... same manner as it would have been performed in the kernel in the MT slot case. ...
    (Linux-Kernel)
  • Re: request_module vs. modprobe blacklist (and security subsystem implications)
    ... That does not belong in the kernel unless there ... some post failure fragile userspace filtering. ... If the kernel is better at filtering than userspace, that is an SELinux ...
    (Linux-Kernel)
  • Re: Normal host or router as a packet filter?
    ... >> depends on the type of filtering the machine offers. ... Ob such a box usually nothing else is running exept the kernel, ... Stateful filtering consumes some memory but that's it. ... packet-filter this might be diffrent. ...
    (comp.security.firewalls)
  • Re: Normal host or router as a packet filter?
    ... > In very many cases there is nothing wrong with non-stateful filtering. ... Why should the native kernel modules for the 2.4.x kernel ... > problem with such machines but hardware failure might be one. ...
    (comp.security.firewalls)