Re: Nokia, Checkpoint, Stone, Linux, Pix

From: gaius.petronius (rut@linuxmail.org)
Date: 01/23/02


From: rut@linuxmail.org (gaius.petronius)
Date: 22 Jan 2002 20:42:19 -0800


> > 2: am i correct in saying that the Nokia 650 essentially is a PC and
> > that a Linux machine running ipchains can do the same job better?
>
> Not with ipchains. iptables yes. iptables is stateful (and better at it
> than checkpoint 4.1).

iptables and ipchains are kernel modules. What feature(s) make(s) one
better than the other?

>
> > 3: does there a exist a *better* technology, a different hardware
> > platform, that outshines all of these firewalling methods?
>
> Have a look at ipf. (ip filter) from Darren Reed. It is blindingly fast
> on an appropriate sun. It will cost you for hardware though.

What makes it better? Do you have the url please?

>
> Look at OpenBSD with either ipf or pf. This too can run on a sun. There
> is no good technical reason not to go with iptables or ipf.
>
> EJ

Try telling that to the potatoes with pointy hair when they receive
laminated advertisements claiming to provide "hardware" firewalls.



Relevant Pages

  • Re: Prevent access to linux server when mac adress does not match ip adress
    ... Iptables has much more features than ipchain. ... Prior to the 2.2.x kernel, the firewall was controlled by "ipfwadm". ... introduced the IPCHAINS tool to control that. ... Often the upgrade is too big and bulky for the older ...
    (comp.os.linux.networking)
  • Re: IPChains with RH 9? "Protocol not available"
    ... Yes, iptables is way more versatile than ipchains, and ipchains ... is no longer supported in the redhat kernel by default. ... is RH 9 stock kernel still support ipchains? ...
    (RedHat)
  • Re: A Question On Ipchains Input Rules
    ... If RH72 allows using iptables instead of ipchains, ... return packets for any established connections, ... outbound SMTP sessions, you just allow outbound SMTP, and the ...
    (comp.os.linux.security)
  • Re: IPChains not working
    ... >>and changing a script from ipchains to iptables can take a while ... The only people for me are the mad ones -- the ones who are mad to live, ... the ones who never yawn or say a commonplace thing, but burn, burn, burn ...
    (comp.os.linux.security)
  • Re: Still getting the same IPTABLES errors in the kernel(2.4.17)
    ... > Did you turn off ipchains. ... >> Perhaps iptables or your kernel needs to be upgraded. ... >> # IP: Netfilter Configuration ...
    (comp.os.linux.security)