1 |
Duncan wrote: |
2 |
> "P.V.Anthony" <pvantony@×××××××××××.sg> posted |
3 |
> 470438AA.8040502@×××××××××××.sg, excerpted below, on Thu, 04 Oct 2007 |
4 |
> 08:49:46 +0800: |
5 |
> |
6 |
> |
7 |
>> I was trying to get the KISS firewall working on Gentoo Hardened amd64. |
8 |
>> |
9 |
> Personally, I tried a number of different firewall scripts, but wasn't |
10 |
> really satisfied with any of them. Most of them tried to do too much -- |
11 |
> they had all sorts of config options for configuring big commercial |
12 |
> networks, options for shutting off net access to a specific segment of |
13 |
> the internal network at a specific time, for instance. I didn't /need/ |
14 |
> that sort of complex configuration, and it only made things more |
15 |
> confusing, not less. |
16 |
> |
17 |
> At the same time, stuff that should have been simple ended up hugely |
18 |
> complex. I was never sure which modules I needed for which options, and |
19 |
> since I was configuring scripts that did the actual configuring of the |
20 |
> IPTables based firewall, when something didn't work, I was never quite |
21 |
> sure whether it was the script, or a bug in the kernel, or a missing |
22 |
> module, or my mistake, or... Well, I'm sure you can identify right about |
23 |
> now! =8^( |
24 |
> |
25 |
I have to disagree with this evaluation. In several years, I found that |
26 |
shorewall makes simple things simple, and difficult things I've never |
27 |
tried. My network is really, really simple: a |
28 |
firewall/fileserver/everything with a slightly defective keyboard that I |
29 |
carry a screen to when it doesn't work, plus a number of other computers |
30 |
(one desktop, three laptops, usually) for various family members. The |
31 |
firewall mainly does three things: |
32 |
1) Block everything except a few services from the outside. |
33 |
2) NAT. |
34 |
3) A few direct port forwards to the desktop computer. |
35 |
|
36 |
Configuring this is easy enough in IPTables (I did learn them somewhat, |
37 |
out of interest, though I've forgotten a lot, too), but it's really, |
38 |
really easy in shorewall. |
39 |
|
40 |
In all the years I've used Gentoo now, I can only say that I'm highly |
41 |
satisfied with the program. The only negative point I can find is that |
42 |
it always wants to overwrite all the configuration files on an upgrade. |
43 |
|
44 |
Sebastian Redl |
45 |
|
46 |
-- |
47 |
gentoo-amd64@g.o mailing list |