1 |
William Kenworthy <billk@×××××××××.au> wrote: |
2 |
> |
3 |
> If you are going to go to this bother ... why not use shorewall, create |
4 |
|
5 |
When I checked for scripts creating rules, none fulfilled my needs. |
6 |
(I do not know whether I checked shorewall at this time). |
7 |
For instance, instead of dropping most packets, I want to reject them |
8 |
properly, only with a rate-limit to avoid DOS. Then there is the |
9 |
mentioned port knocking, some forwarding etc. pp. |
10 |
|
11 |
> a custom configuration for each site (including any changes to services) |
12 |
> and and have your script just copy them in and restart the various |
13 |
> services including shorewall? |
14 |
|
15 |
Instead of managing dozens of configurations manually, |
16 |
I think it is easier to have one script which creates an |
17 |
appropriate custom configuration on all my machines, depending |
18 |
on certain files in /etc and other tests. That's why I always |
19 |
run my firewall script on startup (or if I severely change |
20 |
the configuration). |
21 |
|
22 |
> I use a simple script with autosetup using network-manager |
23 |
|
24 |
network-manager is on my university's laptop (with Ubuntu - |
25 |
not my decision), but on any "safe" machine (running Gentoo) |
26 |
I refuse to install the gaping security hole "polkit" |
27 |
which unfortunately is a hard dependency of network-manager. |
28 |
As soon as "polkit" is on an machine on which you use a browser, |
29 |
it makes no sense to spend time pretending to make it secure: |
30 |
Barring your back door even more when the front door of your house |
31 |
was removed is rather pointless... |