From: Jose Monteiro <jfmonteiro@netvisao.pt>
To: Harald Welte <laforge@netfilter.org>,
netfilter-devel@lists.netfilter.org
Subject: Re: ipt_limit module with sun4u architectures
Date: Thu, 19 Feb 2004 17:50:14 +0000 [thread overview]
Message-ID: <20040219175014.GA12545@primewebs.net> (raw)
In-Reply-To: <20040214202227.GV7756@sunbeam.de.gnumonks.org>
On Sat, Feb 14, 2004 at 09:22:27PM +0100, Harald Welte wrote:
> I'm not aware of any possible workaround that would not make all 32bit
> architectures require to recompile their iptables userspace :(
>
> https://bugzilla.netfilter.org/cgi-bin/bugzilla/show_bug.cgi?id=94
The thing is, old ultrasparcs can be reused as firewalls. But now, the os/software issue comes.
Suppose for instance, that management demands messenger audio/video through the firewall, even after being told about the riscs involved. sysadmins refuse to trade the existing sun4u/ipfilter solution for a m$ one, and they happen to have an unused ultrasparc.
porting intel's upnp sdk for solaris is out of the question, so other unix must be loaded. thinking of a *bsd is pointless because the existing ports of this sdk do not cleanly (if at all) compiles under a sun4u.
So we are left with the linux solution. debian's sparc port is ok, and upnpd/linux-igd compiles fine.
Now comes the iptables logging issue. If we log, the firewall is DoS'ed with a simple nmapping, so ipt_limit must be used, and because it cannot be used in 64bit/kernel 32bit/userland architectures, we are left with a perfectly running firewall but without any logging of its activity.
Since this bug is already very old (2003-05-29), and probably there aren't that few sun4u/linux/iptables users as it could be supposed (partly because of the line of reasoning above, who knows), i was coming for the help of you guys to see if a patch is made available.
Thx,
Jose
next prev parent reply other threads:[~2004-02-19 17:50 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2004-02-10 18:43 ipt_limit module with sun4u architectures Jose Monteiro
2004-02-14 20:22 ` Harald Welte
2004-02-19 17:50 ` Jose Monteiro [this message]
2004-02-19 20:18 ` Henrik Nordstrom
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20040219175014.GA12545@primewebs.net \
--to=jfmonteiro@netvisao.pt \
--cc=laforge@netfilter.org \
--cc=netfilter-devel@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.