Gentoo Archives: gentoo-amd64

From: Sebastian Redl <sebastian.redl@×××××××××××.at>
To: gentoo-amd64@l.g.o
Subject: Re: [gentoo-amd64] Re: KISS firewall not working on Gentoo Hardened
Date: Thu, 04 Oct 2007 19:07:31
Message-Id: 4705370A.4010709@getdesigned.at
In Reply to: [gentoo-amd64] Re: KISS firewall not working on Gentoo Hardened by Duncan <1i5t5.duncan@cox.net>
1 Duncan wrote:
2 > "P.V.Anthony" <pvantony@×××××××××××.sg> posted
3 > 470438AA.8040502@×××××××××××.sg, excerpted below, on Thu, 04 Oct 2007
4 > 08:49:46 +0800:
5 >
6 >
7 >> I was trying to get the KISS firewall working on Gentoo Hardened amd64.
8 >>
9 > Personally, I tried a number of different firewall scripts, but wasn't
10 > really satisfied with any of them. Most of them tried to do too much --
11 > they had all sorts of config options for configuring big commercial
12 > networks, options for shutting off net access to a specific segment of
13 > the internal network at a specific time, for instance. I didn't /need/
14 > that sort of complex configuration, and it only made things more
15 > confusing, not less.
16 >
17 > At the same time, stuff that should have been simple ended up hugely
18 > complex. I was never sure which modules I needed for which options, and
19 > since I was configuring scripts that did the actual configuring of the
20 > IPTables based firewall, when something didn't work, I was never quite
21 > sure whether it was the script, or a bug in the kernel, or a missing
22 > module, or my mistake, or... Well, I'm sure you can identify right about
23 > now! =8^(
24 >
25 I have to disagree with this evaluation. In several years, I found that
26 shorewall makes simple things simple, and difficult things I've never
27 tried. My network is really, really simple: a
28 firewall/fileserver/everything with a slightly defective keyboard that I
29 carry a screen to when it doesn't work, plus a number of other computers
30 (one desktop, three laptops, usually) for various family members. The
31 firewall mainly does three things:
32 1) Block everything except a few services from the outside.
33 2) NAT.
34 3) A few direct port forwards to the desktop computer.
35
36 Configuring this is easy enough in IPTables (I did learn them somewhat,
37 out of interest, though I've forgotten a lot, too), but it's really,
38 really easy in shorewall.
39
40 In all the years I've used Gentoo now, I can only say that I'm highly
41 satisfied with the program. The only negative point I can find is that
42 it always wants to overwrite all the configuration files on an upgrade.
43
44 Sebastian Redl
45
46 --
47 gentoo-amd64@g.o mailing list

Replies