All of lore.kernel.org
 help / color / mirror / Atom feed
From: Kenneth Kalmer <kenneth.kalmer@gmail.com>
To: Agung <duppeh@yahoo.com>
Cc: netfilter@lists.netfilter.org
Subject: Re: macro & iptables
Date: Thu, 8 Sep 2005 23:08:52 +0200	[thread overview]
Message-ID: <fad9d484050908140817c727d5@mail.gmail.com> (raw)
In-Reply-To: <20050831035552.99400.qmail@web53305.mail.yahoo.com>

Agung, Edmundo & Rob

I know the question has been answered but I've got the urge to add my
2c as well.

As a quick background, I've used iptables for several months now and
am quite comfortable in my abilities. This list has helped me a lot,
even just by reading the majority of the posts every day.

I'm learning pf now, been using it for a couple of days only. The
differences between iptables and pf are quite significant. In the past
couple of days if really learned to love pf, over iptables, exactly
for reasons like it's macros and ease of configuration.

For an experiment I tried replacing a very reliable iptables firewall
on a DSL connection with a pf one, and man did I have troubles.

So where pf is easier to configure, with gimmicks like macros and
lists, iptables has unbelievable flexibility even though it is only
executed command by command.

I must admit that I have my own shell scripts that make configuring an
iptables firewall 10 times easier and quicker than a pf one, but yet I
know iptables way better than pf.

Stick to what you know and are comfortable with. Never risk security
for nice features. Both applications are world class, and netfilter
has excellent support!

HTH to clear the air a bit...

Enjoy the weekend

On 8/31/05, Agung <duppeh@yahoo.com> wrote:
> hi there,
> 
> is it possible using macro *like pf did* with iptables
> ?? while i'm googling i found nothing about this, any
> suggestion ?? :-)
> 
> 
> regards,
> Agung
> 
> __________________________________________________
> Do You Yahoo!?
> Tired of spam?  Yahoo! Mail has the best spam protection around
> http://mail.yahoo.com
> 
> 


-- 

Kenneth Kalmer
kenneth.kalmer@gmail.com

Folding@home stats
http://vspx27.stanford.edu/cgi-bin/main.py?qtype=userpage&username=kenneth%2Ekalmer


      parent reply	other threads:[~2005-09-08 21:08 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2005-08-31  3:55 macro & iptables Agung
2005-08-31 11:29 ` /dev/rob0
2005-08-31 14:13   ` Agung
2005-08-31 14:23     ` /dev/rob0
     [not found]     ` <65aa6af905083107354ca663e0@mail.gmail.com>
2005-08-31 14:35       ` Fwd: " Edmundo Carmona
2005-09-01  3:13         ` Agung
2005-09-08 21:08 ` Kenneth Kalmer [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=fad9d484050908140817c727d5@mail.gmail.com \
    --to=kenneth.kalmer@gmail.com \
    --cc=duppeh@yahoo.com \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.