From: "René Pfeiffer" <lynx@luchs.at>
To: netfilter@lists.netfilter.org
Subject: Netfilter rule notation and rule parsers
Date: Mon, 19 Feb 2007 16:25:09 +0100 [thread overview]
Message-ID: <20070219152509.GL19622@nightfall.luchs.at> (raw)
[-- Attachment #1: Type: text/plain, Size: 1357 bytes --]
Hello, Netfilter List!
I have a question regarding the notation of filter rules. I am quite
familiar with the syntax of the iptables command. Apparently most people
who write firewall scripts are familiar with it as well since a lot of
scripts configuring Netfilter rules consist of a shell script and config
scripts. Most people that run a packet filter don't want to delve into
the depths of the iptables syntax in order to change a few rules.
Is anyone on this list aware of projects that try to define a kind of
meta-syntax for filtering rules which can be processed and stored easier
than shell script fragments? Maybe someone has tried to write a parser
in order to import OpenBSD pf or Cisco PIX rules. I'd like to hear about
anyone who has thoughts on this.
I am aware that there are several rule editors out there (such as
FWbuilder). I am more interested in a low-level approach having simple
rules that can be parsed easily and possibly distributed among multiple
firewall systems.
Best wishes,
René.
--
)\._.,--....,'``. Let GNU/Linux work for you while you take a nap.
/, _.. \ _\ (`._ ,. R. Pfeiffer <lynx at luchs.at> + http://web.luchs.at/
`._.-(,_..'--(,_..'`-.;.' - System administration + Consulting + Teaching -
Got mail delivery problems? http://web.luchs.at/information/blockedmail.php
[-- Attachment #2: Type: application/pgp-signature, Size: 189 bytes --]
next reply other threads:[~2007-02-19 15:25 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2007-02-19 15:25 René Pfeiffer [this message]
2007-02-19 19:38 ` Netfilter rule notation and rule parsers Franck Joncourt
2007-02-19 22:54 ` René Pfeiffer
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20070219152509.GL19622@nightfall.luchs.at \
--to=lynx@luchs.at \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.