From: "John A. Sullivan III" <john.sullivan@nexusmgmt.com>
To: netfilter@lists.netfilter.org
Subject: A Humble Proposal
Date: Wed, 24 Sep 2003 06:57:34 -0400 [thread overview]
Message-ID: <1064401053.1892.5.camel@jasiiitosh.nexusmgmt.com> (raw)
What an interesting project! Perhaps nufw and ISCS
(http://iscs.sourceforge.net) can share some ideas. ISCS plans to
support the dynamic creation of iptables rules based upon LDAP, AD, NDS,
SecureID and RADIUS in version 2.x. It currently supports the dynamic
creation of iptables rules based upon the fields of a user's X.509
digital certificate. The scripts to make this happen on the enforcement
device are in the project CVS but we are still building the
administrative interface. In fact, we may be looking to hire a few
developers to accelerate this process. Please feel free to use the
scripts if they are of help - John
--
John A. Sullivan III
Chief Technology Officer
Nexus Management
+1 207-985-7880
john.sullivan@nexusmgmt.com
---
If you are interested in helping to develop a GPL enterprise class
VPN/Firewall/Security device management console, please visit
http://iscs.sourceforge.net
> I have seen some of this functionality in Checkpoint, and I think
that> it would be immensely useful in the iptables community if it is
adopted.
NuFW provides these sort of things :
http://www.nufw.org
Code can be considered has beta code. It works but things need to be
done (especially a Windows Client ;-).
With NuFW, you really filter by User (Group) and not by IP as it often
the case.
next reply other threads:[~2003-09-24 10:57 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2003-09-24 10:57 John A. Sullivan III [this message]
-- strict thread matches above, loose matches on Subject: below --
2003-09-26 11:53 A Humble Proposal John A. Sullivan III
2003-09-26 0:19 A humble proposal Daniel Chemko
2003-09-26 7:21 ` Eric Leblond
2003-09-23 16:13 Daniel Chemko
2003-09-23 16:39 ` Eric Leblond
2003-09-23 21:10 ` Joel Newkirk
2003-10-02 19:51 ` Harald Welte
2003-10-02 21:26 ` Eric Leblond
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1064401053.1892.5.camel@jasiiitosh.nexusmgmt.com \
--to=john.sullivan@nexusmgmt.com \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox