1 |
On Tuesday 19 Feb 2013 16:20:20 James wrote: |
2 |
> Alon Bar-Lev <alonbl <at> gentoo.org> writes: |
3 |
> > Yes, I use it. |
4 |
> > Just enable all non experimental iptables settings at kernel including |
5 |
> > NAT. |
6 |
> |
7 |
> A while back, Mick posted on some updates to Arno's firewall work: |
8 |
> |
9 |
> net-firewall/arno-iptables-firewall |
10 |
> |
11 |
> I do not have the info handy, but you could google it |
12 |
> or maybe mick can post the link again.... |
13 |
> |
14 |
> I found Arno's approach very instructive for rule making, |
15 |
> research and as a reference. |
16 |
> |
17 |
> That said, firewalls and transparent bridges are moving forward |
18 |
> at the speed of light. Many new featuures in the kernel |
19 |
> as wells a different approaches to security. If you intend |
20 |
> to "hack" in this area, you need to get current and find a |
21 |
> compatible group for the latest information.... |
22 |
> |
23 |
> good hunting.....as it is very time consuming |
24 |
> |
25 |
> ymmv, |
26 |
> James |
27 |
|
28 |
Here it is, I'm just trying the latest ~2.0.1d version as we speak, which also |
29 |
includes IPv6 rules: |
30 |
|
31 |
http://rocky.eld.leidenuniv.nl/joomla/index.php?option=com_content&view=article&id=45&Itemid=63 |
32 |
|
33 |
-- |
34 |
Regards, |
35 |
Mick |