Gentoo Archives: gentoo-user

From: Walter Dnes <waltdnes@××××××××.org>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] IPCHAINS or other alternative firewalls or packet-filters?
Date: Thu, 20 Aug 2009 02:25:42
Message-Id: 20090820022605.GA9163@waltdnes.org
In Reply to: Re: [gentoo-user] IPCHAINS or other alternative firewalls or packet-filters? by Dan Farrell
1 On Tue, Aug 18, 2009 at 06:17:47PM -0500, Dan Farrell wrote
2
3 > I too am a minimalist but I think you've got iptables misidentified.
4 > It has lots of features; that's not the same as saying it's bloated.
5 > More like the linux kernel (and in fact it _is_, as others have said,
6 > the linux kernel) - it supports a lot of different functionality. If
7 > you don't want a particular capability, disable it in the kernel.
8
9 Alan and Dan
10
11 I can set rules OK. My problem is figuring out which capabilities to
12 build or not build in order to create a firewall. I.e. I need a
13 menuconfig guide not an iptables rules front end.
14
15 > If you want a quick firewall setup, use
16 > http://spore.ath.cx/~dan/doc/home-firewall.html. It's what I use and
17 > my step by step guide should save you a bit of effort.
18
19 OK I'll follow your section listing for most of the necessary
20 menuconfig items, but I'll drop the NAT support. Is there any reason
21 you build modules rather than directly into the kernel?
22
23
24 Last minute addendum; saying "No" to
25 [ ] Advanced netfilter configuration
26 greatly reduces the number of options showing up. I think this is what
27 I was looking for.
28
29 --
30 Walter Dnes <waltdnes@××××××××.org>