From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Taylor, Grant" Subject: Re: Possibility to lock iptables rules. Date: Wed, 20 Apr 2005 17:16:00 -0500 Message-ID: <4266D4A0.2000706@riverviewtech.net> References: <1113994155.31280.29.camel@localhost.localdomain> <20050420184753.GA25069@bender.817west.com> <20050420220123.GA25652@bender.817west.com> Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: <20050420220123.GA25652@bender.817west.com> List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: netfilter-bounces@lists.netfilter.org Errors-To: netfilter-bounces@lists.netfilter.org Content-Type: text/plain; charset="us-ascii"; format="flowed" To: Jason Opperisano Cc: netfilter@lists.netfilter.org > after pondering this further (post-post, natch)...i had a thought > (yes--it hurt). you could probably use SELinux to achieve this. the > minimal benefits that others have pointed out, and the overly complex > nature of SELinux probably yields a pretty low benefit/cost ratio, > though. Want some ice? Eh, the benefit / cost ratio might be low, but we are hackers and we do what we do for the challenge / fun / bragging rights of it. Grant. . . .