Gentoo Archives: gentoo-user

From: Martin Vaeth <vaeth@××××××××××××××××××××××××.de>
To: gentoo-user@l.g.o
Subject: [gentoo-user] Re: scripted iptables-restore
Date: Mon, 14 Oct 2013 12:08:59
Message-Id: slrnl5nnlt.hoa.vaeth@bois.imp.fu-berlin.de
In Reply to: Re: [gentoo-user] Re: scripted iptables-restore by William Kenworthy
1 William Kenworthy <billk@×××××××××.au> wrote:
2 >
3 > If you are going to go to this bother ... why not use shorewall, create
4
5 When I checked for scripts creating rules, none fulfilled my needs.
6 (I do not know whether I checked shorewall at this time).
7 For instance, instead of dropping most packets, I want to reject them
8 properly, only with a rate-limit to avoid DOS. Then there is the
9 mentioned port knocking, some forwarding etc. pp.
10
11 > a custom configuration for each site (including any changes to services)
12 > and and have your script just copy them in and restart the various
13 > services including shorewall?
14
15 Instead of managing dozens of configurations manually,
16 I think it is easier to have one script which creates an
17 appropriate custom configuration on all my machines, depending
18 on certain files in /etc and other tests. That's why I always
19 run my firewall script on startup (or if I severely change
20 the configuration).
21
22 > I use a simple script with autosetup using network-manager
23
24 network-manager is on my university's laptop (with Ubuntu -
25 not my decision), but on any "safe" machine (running Gentoo)
26 I refuse to install the gaping security hole "polkit"
27 which unfortunately is a hard dependency of network-manager.
28 As soon as "polkit" is on an machine on which you use a browser,
29 it makes no sense to spend time pretending to make it secure:
30 Barring your back door even more when the front door of your house
31 was removed is rather pointless...

Replies

Subject Author
Re: [gentoo-user] Re: scripted iptables-restore William Kenworthy <billk@×××××××××.au>