Linux Netfilter discussions
 help / color / mirror / Atom feed
* more questions about kernel config options for iptables
@ 2003-04-07 21:18 Robert P. J. Day
  2003-04-08  7:04 ` Joel Newkirk
  0 siblings, 1 reply; 15+ messages in thread
From: Robert P. J. Day @ 2003-04-07 21:18 UTC (permalink / raw)
  To: iptables mailing list


  having poked around even more in the options, i must say
i'm a little puzzled.  mostly, i'm interested in understanding
what some of these options do all by themselves, so forgive me
if i end up repeating myself.

  first, the basic Connection tracking option claims to be
necessary for masq/NAT.  what value is that option if it is
the only one selected?  it may be *necesasry* for masq/NAT,
but it certainly doesn't seem to be *sufficient*.  what is
the value of selecting that single option to the exclusion
of all others.  what does it allow you to do?

  next, notice that "IP tables support" also claims to be
necessary for masq/NAT.  if that's the case, it would seem
that these two options should somehow be interdependent.

  another way of looking at it might be, why would anyone
select "Connection tracking in the first place"?  might it
not be more reasonable to have the user select the 
*functionality* they want, and have something like
that basic connection tracking option as an invislble
dependency?

  to that end, it would make more sense to have a restructured
menu with more obvious options like

  Basic filtering
  Simple NAT
  Masquerading

and so on.  the actual object files associated with these
*functions* are of no interest to the user.  he/she cares
only about what can be done afterwards.

  here's another question.  notice the options under 
"Connection tracking".  first, i'm aware that because of 
the way FTP works, you need some connection tracking ability
to filter it properly.  so this is just straight FTP
filtering.

  note, however, that the next three options -- IRC,
TFTP and Amanda -- refer to using those protocols
in conjunction with NAT or masquerading.  if this is
the case, i can see having FTP in one submenu associated
with filtering, with the others in a submenu associated
with NAT/masq.  it just seems to make more sense that way.

  anyway, comments?

rday



^ permalink raw reply	[flat|nested] 15+ messages in thread
* RE: more questions about kernel config options for iptables
@ 2003-04-08 16:03 Daniel Chemko
  0 siblings, 0 replies; 15+ messages in thread
From: Daniel Chemko @ 2003-04-08 16:03 UTC (permalink / raw)
  To: Robert P. J. Day; +Cc: iptables mailing list

Yes, but it is ok. They are just letting us know that they miss not
being able to read all the juicy new iptables gossip. When they return,
I am sure they will have a nice inbox full of Iptables goodness (unless
they got fired!).

	p.s.  is the rest of this list also getting auto-vacation
messages
	from respond-dgour?  just wondering if it's coming from *this*
	list.





^ permalink raw reply	[flat|nested] 15+ messages in thread

end of thread, other threads:[~2003-04-09  1:25 UTC | newest]

Thread overview: 15+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-04-07 21:18 more questions about kernel config options for iptables Robert P. J. Day
2003-04-08  7:04 ` Joel Newkirk
2003-04-08  7:44   ` Joel Newkirk
2003-04-08 11:17     ` Arnt Karlsen
2003-04-08 11:01   ` Robert P. J. Day
2003-04-08 11:55     ` Cedric Blancher
2003-04-08 12:23       ` Robert P. J. Day
2003-04-08 12:59         ` Cedric Blancher
2003-04-08 13:04           ` Robert P. J. Day
2003-04-08 13:54           ` Robert P. J. Day
2003-04-08 15:09             ` Joel Newkirk
2003-04-08 15:11               ` Robert P. J. Day
2003-04-08 18:27                 ` OT: video cards, was: " Arnt Karlsen
2003-04-09  1:25               ` indev/outdev_name? Scott MacKay
  -- strict thread matches above, loose matches on Subject: below --
2003-04-08 16:03 more questions about kernel config options for iptables Daniel Chemko

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox