All of lore.kernel.org
 help / color / mirror / Atom feed
* IPTables Feature set and performance.
@ 2002-12-02 21:33 hard__ware
  2002-12-02 23:22 ` Michael
  0 siblings, 1 reply; 4+ messages in thread
From: hard__ware @ 2002-12-02 21:33 UTC (permalink / raw)
  To: ccmike; +Cc: netfilter

I belive you cant Mangle Packets as well on PIX Firewall
Such as TTL Values & MSS Clamps,

here are some things on why i consider netfilter over any other product for
now ..

1) its easy to understand & it works well
2) Completely Open Source Project
3) Using the help from www.lartc.org QoS can be seamlessly intergrated

4) Squid + Netfilter also offers more advantages like
Speedy Web Cache & ACL Rules to Block ADs ect,

5) IPTState is a good utillity for showing your Connections Through & Too
your netfilter firewall

6) IPTables Allows you to set Variables for its ip_conntrack_helpers such as
ftp & irc like,
the Default Port No: to track is 21 this can be changed to Many or Just One
using sysctrl options

7) Kernel Level Networking & Filtering /w Linux ..
have you got a problem, well if your good enough you
can make changes to your kernel / modules that will
improve / manipulate the way your IP V4 Box works.

hope this helps a bit,

Hard__warE


^ permalink raw reply	[flat|nested] 4+ messages in thread
* IPTables Feature set and performance.
@ 2002-12-02 18:25 ccmike
  0 siblings, 0 replies; 4+ messages in thread
From: ccmike @ 2002-12-02 18:25 UTC (permalink / raw)
  To: netfilter

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


O wise netfilter guruz, I pray unto thee in hopes you can answer my most 
humble questions. 

I have been all over the net and looked thru the mailing list archives, but 
cannot find an answer to questions that have been asked a number of times, 
but never with the proper specifications, so I will attempt to ask in a more 
proper form.

First: netfilter vs pix

considering packet filtering only, and ignoring the "extra" things such as vpn 
and pretty gui, administration costs, purchase price, and CYA.

What things can I do with an iptables firewall that I cannot do with a pix 
firewall,  I know about log tagging, but what else?

If the "costs" are not an issue, and the cisco extras are not necessary, would 
you go with a pix or a netfilter solution and why? (skip the 'cause linux 
rulez answers).

It seems that every time that this question was asked in the past the answer 
was "pix comes with cisco CYA", or "what about the admin overhead", or 
"depends on your requirements".  I am interested (as I am sure others are) in 
the technical differences.  I am not trying to build a business case.  

Second: Performance

If I make a monolithic kernel with everything stripped out of it except for 
the code I need to run a netfilter firewall with stateful inspection, and I 
have only the basic ruleset (everything out, established+mail+web+ssh in, 
drop illegal ip addresses and flag combinations). basically a network noise 
filter. How many new connections per second can I expect to handle on what 
type of box?  What type of thruput should I expect on what type of box?

Please note, I have both types of firewalls, and I am just trying to plan out 
how many of what I should put where and why.  I really would prefer to use 
netfilter over pix, it will be an educational exercise for me.  I can D/L 
freeswan, and all the other goodies, and have plenty of boxen lying around 
collecting dust, lots of time and get paid no matter what I decide to do (see 
sig).

There has to be someone, somewhere, who understands what I am asking and has 
the answers.  I have the asbestos underwear properly installed, so flame on. 
I will summarize back to the list.

- -- 
Mike Taylor.  GSEC          Non Impediti Ratione Cogitationis
Coordinator of Systems Administration and Network Security
Indiana State University.                      Rankin Hall Rm 039
210 N 7th St.                                           Terre Haute, IN.
Voice: 812-237-8843
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.7 (GNU/Linux)

iD8DBQE966WlknPysOadsKcRAj8HAJ0fYo3EBa9dcjKB/rbwcNRCKE+RpwCgulCb
38DjnIigdHaCkyWmWbpkyNA=
=mReT
-----END PGP SIGNATURE-----


^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2002-12-04 13:17 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2002-12-02 21:33 IPTables Feature set and performance hard__ware
2002-12-02 23:22 ` Michael
2002-12-04 13:17   ` Roberto Nibali
  -- strict thread matches above, loose matches on Subject: below --
2002-12-02 18:25 ccmike

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.