Gentoo Archives: gentoo-dev

From: Collins Richey <erichey2@××××.com>
To: gentoo-dev@××××××××××.org
Subject: Re: [gentoo-dev] NAT iptables info
Date: Wed, 03 Oct 2001 18:11:50
Message-Id: 20011003182513.5af6a97e.erichey2@home.com
In Reply to: Re: [gentoo-dev] NAT iptables info by Michael M Nazaroff
1 On Wed, 3 Oct 2001 12:51:07 -0700 Michael M Nazaroff
2 <naz@×××××××××××××××××.et> wrote:
3
4 > On Wednesday 03 October 2001 12:34 pm, you wrote:
5 > Just to let everyone know I completely agree with Donny on
6 > this...Gentoo
7 > should be power house not dumbed down.
8 >
9 > > Nope. Sorry. Im not in agreement in this at all. Of course, its
10 > open to
11 > > debate, Im not saying I know everything, nor Im 100% right. Go
12 > ahead,
13 > > debate away. But I dont want any part of it, Ill tell you that!
14 > >
15 > > If you dont understand the ramnifications of packet filetering,
16 > NAT, etc
17 > > then you have *no* business running this software. We are not
18 > Microsoft or
19 > > Wingate, opening yuor machine to a wider world.
20 > >
21 > > What if somebodys iptables script is made into an ebuild, and said
22 > script
23 > > turns out to be flawed, perhaps seriously? Then its "hey, yeah
24 > those guys
25 > > at gentoo have a firewall setup like swiss cheese.". What
26 > interfaces are
27 > > yuo going to configure this ebuild for? eth0 and eth1? how about
28 > ppp? maybe
29 > > an isdn interface? How do yuo choose? Im going to say this again,
30 > it is
31 > > %100 configuration. This is *not* the domain of a package. It is
32 > the domain
33 > > of a system administrator. This is 1 file we're talking about here
34 > people,
35 > > not a series of docs, scripts, config files. *most* of them
36 > anyway. There
37 > > *are* some that come with external configs. But thats all beside
38 > the point.
39 > > The script needs to be edited. This whole thing started because we
40 > > basically had a post to the devel list of the flavour: "I need an
41 > iptables
42 > > HOWTO".
43 > >
44 > > What are you going to do about the kernel modules? Did you know
45 > that
46 > > the netfilter modules are built at the kernel level? How are you
47 > going to
48 > > DEPEND on that?
49 > >
50 > > This is bad policy. A distribution should *not* be dictating
51 > *policy*. To
52 > > not understand that is a big mistake. Listen, Redhat and Mandrake
53 > are
54 > > the kinds of distros doing this stuff! Making Linux into a 1-click
55 > affair.
56 > > This is not our primary intention. Not at this stage anyway!
57 > >
58 > > So feel free to debate it all you want, I wont be having *any*
59 > part in it
60 > > Ill tell you that!
61 > >
62
63 Yep, I agree too. This really needs to be
64 documentation-documentation-documentation. There should be HOWTOs
65 tailored to the gentoo way for most of the things everyone would like
66 to do.
67
68 --
69 Collins Richey
70 Denver Area
71 gentoo_rc6 xfce+sylpheed