From: Tom Eastep <teastep@shorewall.net>
To: Ray Anderson <rsa@prideindustries.com>, netfilter@lists.netfilter.org
Subject: Re: Shorewall vs. Iptables
Date: Thu, 12 Feb 2004 13:56:56 -0800 [thread overview]
Message-ID: <200402121356.56294.teastep@shorewall.net> (raw)
In-Reply-To: <004201c3f1af$b16d7fa0$2405010a@rsa>
On Thursday 12 February 2004 01:32 pm, Ray Anderson wrote:
> Is any one better than the other?
>
> I'm currently running a RedHat box that's soon to be replaced with a
> Mandrake machine. Of course I threw out the Shorewall stuff in favor of
> manually implementing the same Iptables ruleset(s) that I have for the RH
> machine.
Who wouldn't? :-)
Actually, I recommend against using the Mandrake Shorewall two-interface
configuration.
a) it matches my documentation enough that cutting and pasting from the
documentation doesn't produce errors; but
b) it is different enough that the such cutting and pasting doesn't produce
the desired results.
>
> Does Shorewall give any more protection or is it a simply complicated
> front-end to iptables?
My opinion is far from unbiased but here goes. Shorewall is a high-level tool
for configuring netfilter. It uses the iptables utility to do so. As a
result, it cannot offer any more protection than the iptables utility used
alone can provide.
As for being complicated, if you already understand iptables then Shorewall
would be something else to learn. If you don't, then most people find
Shorewall easier to learn. I definitely believe it to be easier to set up
complex router/firewall configurations using Shorewall than it is using
iptables directly unless you have spent a long time developing your own very
flexible firewall/router framework (in other words, your own Shorewall-like
facility).
-Tom
--
Tom Eastep \ Nothing is foolproof to a sufficiently talented fool
Shoreline, \ http://shorewall.net
Washington USA \ teastep@shorewall.net
next prev parent reply other threads:[~2004-02-12 21:56 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2004-02-12 21:32 Shorewall vs. Iptables Ray Anderson
2004-02-12 21:56 ` Tom Eastep [this message]
2004-02-12 22:17 ` David Cary Hart
2004-02-12 22:21 ` Tom Eastep
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=200402121356.56294.teastep@shorewall.net \
--to=teastep@shorewall.net \
--cc=netfilter@lists.netfilter.org \
--cc=rsa@prideindustries.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox