netfilter-devel.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* Netfilter API and  a New firewall implementation
@ 2007-02-19  8:31 Tharanga
  0 siblings, 0 replies; only message in thread
From: Tharanga @ 2007-02-19  8:31 UTC (permalink / raw)
  To: netfilter-devel

Dear All,

Iam Tharanga and currenty a computer science student. Iam going to implement
a distributed firewall on linux 2.6.X kernel  (As my research project ). and
after reading lot of materials thought to use netfilter frame work. my main
objective is to build a centralized policy management server and
unicast/multicast rules propagation algoritm to its peer nodes.(update peer
nodes)

You guys are experts on this.but still i dont know how to block packets in
realtime withoout restarting my program or unloading/loading modules. its
basically like IPTABLES -A option . so please expalin me how to append a
firewall rule (iam not using IPTABLES, going to use my own firewall ) to my
program. so once the peer node receive the new rule from the polcy
management server it can block that traffic realtime.

and also i  like to know some suggestions from you guys abot my distributed
firewall please let me know ur comments on that so i can add more features
to that implementation.

thought to add

centrilized policy manager (it handles distributed server firewall rules,
one zone file for each host with its policies like DNS zone concept)
centralized firewall monitoring module  (php and AJAX based) / integrating
with Opensource SMS gateway and admininstraotrs can query the firewall
status via SMS

secure protocol to distribute firewall rules among peers.  in order to
prevent man-in the middle attacks and firewall poisoning.

sorry for the huge mail..please help me to achive my objectives..

Many thanks and have a great day !

Tharanga

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2007-02-19  8:31 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2007-02-19  8:31 Netfilter API and a New firewall implementation Tharanga

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).