All of lore.kernel.org
 help / color / mirror / Atom feed
From: Peter Surda <surda@shurdix.com>
To: netfilter-devel@lists.netfilter.org
Subject: Re: Question, my modifed -j LOG
Date: Sun, 21 Aug 2005 04:41:28 +0200	[thread overview]
Message-ID: <20057214412813341@mail.routehat.org> (raw)
In-Reply-To: <4307CA57.9090600@gmx.net>

On Sun, 21 Aug 2005 02:27:03 +0200 Carl-Daniel Hailfinger
<c-d.hailfinger.devel.2005@gmx.net> wrote:

>Jan Engelhardt schrieb:
>> The question is: how different do all these 2000+ hosts need to be
>> classified?
>> I can't think of anything but to let everything through with possibly
>  ^^^^^^^^^^^^^^^^^^^^^^^^^
>> exceptions like SMTP and HTTP (going over proxies there).
>You haven't yet managed such a big student network, right?
Well, he perhaps hadn't, but I did and still do, several of them.

>being able to freely roam and still get access to their own services and
>having different rules, shaping based on traffic history, IP, port and
>building they're sitting in, DoS protection for the hosts behind, limits
>on filesharing, redirection of a few services, exceptions to all the
>rules above because of people being "important", load distribution etc.
I thought this for several years too. Then I discovered WRR and was able to
achieve much better results (both subjective perception of users and
measurements), not to mention that the required administration is much lower.

>Please don't criticize other people before understanding their problems.
You are of course right, original poster's situation seems very complex and such
a large amount of rules may be justified.

Furthermore may I suggest that only development be discussed here and not "how
to use iptables properly"? LARTC might be a better place for that.

>Regards,
>Carl-Daniel
Yours sincerely,
Peter

-- 
http://www.shurdix.org - Linux distribution for routers and firewalls

  reply	other threads:[~2005-08-21  2:41 UTC|newest]

Thread overview: 12+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2005-08-20 17:28 Question, my modifed -j LOG Joakim Axelsson
2005-08-20 20:01 ` Jan Engelhardt
2005-08-20 20:25   ` Joakim Axelsson
2005-08-20 22:14     ` Joakim Axelsson
2005-08-20 22:38     ` Jan Engelhardt
2005-08-21  0:27       ` Carl-Daniel Hailfinger
2005-08-21  2:41         ` Peter Surda [this message]
2005-08-21  4:37       ` Joakim Axelsson
2005-08-21  8:36         ` Jan Engelhardt
2005-08-21 18:30         ` Carl-Daniel Hailfinger
2005-08-21 19:12           ` Joakim Axelsson
2005-08-21 14:16 ` Robbie Dinn

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20057214412813341@mail.routehat.org \
    --to=surda@shurdix.com \
    --cc=netfilter-devel@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.