1 |
On Wednesday 09 December 2015 11:56:39 Andrew Savchenko wrote: |
2 |
|
3 |
> ... Also it is much better to write iptables / iproute / |
4 |
> tc rules manually then using high level generators like shorewall — |
5 |
> this will give you a good understanding on what is going on and how |
6 |
> to optimize or tighten your setup. |
7 |
|
8 |
I don't often disagree with a Gentoo dev, but if I were to attempt this I'd |
9 |
certainly make a hash of it, and we're often told that a badly set up |
10 |
firewall is worse than none. |
11 |
|
12 |
I've been very happy with shorewall for many years and I intend to continue |
13 |
with it. |
14 |
|
15 |
-- |
16 |
Rgds |
17 |
Peter |