Linux Netfilter discussions
 help / color / mirror / Atom feed
From: Antony Stone <Antony@Soft-Solutions.co.uk>
To: netfilter@lists.netfilter.org
Subject: Re: inner workings of IP tables
Date: Mon, 30 Sep 2002 00:52:40 +0100	[thread overview]
Message-ID: <20020929235243.RXLC6699.mta01-svc.ntlworld.com@there> (raw)
In-Reply-To: <Pine.LNX.4.40.0209291918280.19073-100000@klepto.security.algx.lan>

On Monday 30 September 2002 12:37 am, Kevin Dwyer wrote:

> Sorry to barge in, but included are some comments I thought must be made.

No problem - it's a public mailing list :-)

> Not that a GUI makes a good firewall.  Aren't you pretty much dead in the
> water with checkpoint if you don't have access to their GUI?  I know you
> can fw load policies, and possibly even compile them via CLI, but I
> challenge you to make competent ruleset changes with vi on checkpoint.

Yes, and the choice of platforms for the GUI is much smaller than for the 
firewall product itself.   FW-1 runs (to my knowledge, possibly more now) on 
Windows, Solaris, RH Linux and Nokia IPSO.   The GUI runs on Windows.

Okay, there *is* a version of the GUI for Solaris, but it's horrible, and is 
missing quite a number of the features of the version they want you to 
use.....

> Netfilter doesn't have the code to pass the state table across machines
> (and would be a neat feature) but you can make a firewall pair by either
> using VRRPd or Linux-HA.  You'll drop active connections, but CP did too
> up until recently I think.

No, I think CP FW-1 has pretty much had state table synchronisation for as 
long as they've been supporting things like Stonebeat and VRRP to provide the 
failover.   They've certainly had it for the past 5 years.

> > > Management of firewalls.
>
> ..is made more difficult with their reliance on a GUI, IMO.

Hmmm.   It looks easier and gives you "point-and-click" (over)confidence, but 
I agree that if you lose the GUI, you're stuffed.

> ..is made more difficult with their licensing schemes.

Pay them enough $$$ and you get an unlimited licence, full VPN, decent 
encryption.   I'd prefer to use netfilter and spend the money on a house.

> ..is made more difficult when you upgrade the GUI and magically things
> like Manual IPSEC (and who knows what else) disappear.

Hmmm.   I haven't seen that, but then I haven't played with FWng.   As you 
say, though, with a GUI-based product you're at the vendor's mercy how easy 
they make it for you to get at different parts and set things the way you 
want.   At least with a CLI you're in full control, even if you need to learn 
a bit more syntax before you start typing.

Antony.

-- 

Abandon hope, all ye who enter here.
You'll feel much better about things once you do.


  reply	other threads:[~2002-09-29 23:52 UTC|newest]

Thread overview: 13+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2002-09-28 14:11 inner workings of IP tables Naleendra
2002-09-29  9:19 ` Antony Stone
2002-09-29 19:05   ` Mitesh P Choksi
2002-09-29 19:30     ` Antony Stone
2002-09-29 23:37       ` Kevin Dwyer
2002-09-29 23:52         ` Antony Stone [this message]
2002-09-30  1:11           ` Kevin Dwyer
2002-09-30  3:16             ` Vadim Kurland
2002-09-30 13:21               ` Kevin Dwyer
2002-09-30 13:36                 ` Antony Stone
2002-09-30 17:34                 ` Vadim Kurland
2002-09-30 17:49         ` Matthew G. Marsh
2002-10-01  5:51         ` Julian Gomez

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20020929235243.RXLC6699.mta01-svc.ntlworld.com@there \
    --to=antony@soft-solutions.co.uk \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox