From: Charles Jones <linuxchuck@gmail.com>
To: netfilter@lists.netfilter.org
Subject: [announce] Frankenwall released to the public
Date: Mon, 20 Jun 2005 16:46:05 -0500 [thread overview]
Message-ID: <9630799505062014462e0f3fd7@mail.gmail.com> (raw)
Hello list,
Long time lurker here, first time poster...
After much peer-pressure, I have just "GPL'd" and released a bash
script that generates what I hope to be highly secure iptables
rulesets for very "network conscious" system administrators called
"Frankenwall".
Frankenwall creates IPSEC-aware (using the mark target in the mangle
chain) SNAT/Masq/Routing-capable iptables rules. It also supports the
creation of Screened Subnets, port-forwarding, 1:1 static NAT,
standard routing, Ingress/Egress filtering, and MAC Whitelisting.
There are probably other features, but I don't recall them off the top
of my head. See the README, and the in-line documentation in the
script itself for more details.
Please be warned:
The focus of this script is security. If you don't specifically
permit a certain type of traffic, it will most likely not be allowed
through. This means that if you don't understand some of the
intricacies of how the protocols on your network work, or even what
protocols are used, this script is not for you.
With that being said, here is the link:
http://sourceforge.net/projects/frankenwall
I would greatly appreciate any and all constructive criticism (with
suggestions please) on this script. Questions about it or it's
configuration are also welcome.
Thanks for your time,
Charles Jones
reply other threads:[~2005-06-20 21:46 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=9630799505062014462e0f3fd7@mail.gmail.com \
--to=linuxchuck@gmail.com \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.