From: Antony Stone <Antony@Soft-Solutions.co.uk>
To: netfilter@lists.netfilter.org
Subject: Re: inner workings of IP tables
Date: Mon, 30 Sep 2002 00:52:40 +0100 [thread overview]
Message-ID: <20020929235243.RXLC6699.mta01-svc.ntlworld.com@there> (raw)
In-Reply-To: <Pine.LNX.4.40.0209291918280.19073-100000@klepto.security.algx.lan>
On Monday 30 September 2002 12:37 am, Kevin Dwyer wrote:
> Sorry to barge in, but included are some comments I thought must be made.
No problem - it's a public mailing list :-)
> Not that a GUI makes a good firewall. Aren't you pretty much dead in the
> water with checkpoint if you don't have access to their GUI? I know you
> can fw load policies, and possibly even compile them via CLI, but I
> challenge you to make competent ruleset changes with vi on checkpoint.
Yes, and the choice of platforms for the GUI is much smaller than for the
firewall product itself. FW-1 runs (to my knowledge, possibly more now) on
Windows, Solaris, RH Linux and Nokia IPSO. The GUI runs on Windows.
Okay, there *is* a version of the GUI for Solaris, but it's horrible, and is
missing quite a number of the features of the version they want you to
use.....
> Netfilter doesn't have the code to pass the state table across machines
> (and would be a neat feature) but you can make a firewall pair by either
> using VRRPd or Linux-HA. You'll drop active connections, but CP did too
> up until recently I think.
No, I think CP FW-1 has pretty much had state table synchronisation for as
long as they've been supporting things like Stonebeat and VRRP to provide the
failover. They've certainly had it for the past 5 years.
> > > Management of firewalls.
>
> ..is made more difficult with their reliance on a GUI, IMO.
Hmmm. It looks easier and gives you "point-and-click" (over)confidence, but
I agree that if you lose the GUI, you're stuffed.
> ..is made more difficult with their licensing schemes.
Pay them enough $$$ and you get an unlimited licence, full VPN, decent
encryption. I'd prefer to use netfilter and spend the money on a house.
> ..is made more difficult when you upgrade the GUI and magically things
> like Manual IPSEC (and who knows what else) disappear.
Hmmm. I haven't seen that, but then I haven't played with FWng. As you
say, though, with a GUI-based product you're at the vendor's mercy how easy
they make it for you to get at different parts and set things the way you
want. At least with a CLI you're in full control, even if you need to learn
a bit more syntax before you start typing.
Antony.
--
Abandon hope, all ye who enter here.
You'll feel much better about things once you do.
next prev parent reply other threads:[~2002-09-29 23:52 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2002-09-28 14:11 inner workings of IP tables Naleendra
2002-09-29 9:19 ` Antony Stone
2002-09-29 19:05 ` Mitesh P Choksi
2002-09-29 19:30 ` Antony Stone
2002-09-29 23:37 ` Kevin Dwyer
2002-09-29 23:52 ` Antony Stone [this message]
2002-09-30 1:11 ` Kevin Dwyer
2002-09-30 3:16 ` Vadim Kurland
2002-09-30 13:21 ` Kevin Dwyer
2002-09-30 13:36 ` Antony Stone
2002-09-30 17:34 ` Vadim Kurland
2002-09-30 17:49 ` Matthew G. Marsh
2002-10-01 5:51 ` Julian Gomez
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20020929235243.RXLC6699.mta01-svc.ntlworld.com@there \
--to=antony@soft-solutions.co.uk \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox