Linux Netfilter discussions
 help / color / mirror / Atom feed
* Shorewall vs. Iptables
@ 2004-02-12 21:32 Ray Anderson
  2004-02-12 21:56 ` Tom Eastep
  0 siblings, 1 reply; 4+ messages in thread
From: Ray Anderson @ 2004-02-12 21:32 UTC (permalink / raw)
  To: netfilter

Is any one better than the other?

I'm currently running a RedHat box that's soon to be replaced with a
Mandrake machine.  Of course I threw out the Shorewall stuff in favor of
manually implementing the same Iptables ruleset(s) that I have for the RH
machine.

Does Shorewall give any more protection or is it a simply complicated
front-end to iptables?

Cheers,

-=Ray
---------------------------------------
When reaching a stalemate, win with a technique the enemy does not expect.
Miyamoto Musashi



^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: Shorewall vs. Iptables
  2004-02-12 21:32 Shorewall vs. Iptables Ray Anderson
@ 2004-02-12 21:56 ` Tom Eastep
  2004-02-12 22:17   ` David Cary Hart
  0 siblings, 1 reply; 4+ messages in thread
From: Tom Eastep @ 2004-02-12 21:56 UTC (permalink / raw)
  To: Ray Anderson, netfilter

On Thursday 12 February 2004 01:32 pm, Ray Anderson wrote:
> Is any one better than the other?
>
> I'm currently running a RedHat box that's soon to be replaced with a
> Mandrake machine.  Of course I threw out the Shorewall stuff in favor of
> manually implementing the same Iptables ruleset(s) that I have for the RH
> machine.

Who wouldn't? :-)

Actually, I recommend against using the Mandrake Shorewall two-interface 
configuration.

a) it matches my documentation enough that cutting and pasting from the 
documentation doesn't produce errors; but
b) it is different enough that the such cutting and pasting doesn't produce 
the desired results.

>
> Does Shorewall give any more protection or is it a simply complicated
> front-end to iptables?

My opinion is far from unbiased but here goes. Shorewall is a high-level tool 
for configuring netfilter. It uses the iptables utility to do so. As a 
result, it cannot offer any more protection than the iptables utility used 
alone can provide.

As for being complicated, if you already understand iptables then Shorewall 
would be something else to learn. If you don't, then most people find 
Shorewall easier to learn. I definitely believe it to be easier to set up 
complex router/firewall configurations using Shorewall than it is using 
iptables directly unless you have spent a long time developing your own very 
flexible firewall/router framework (in other words, your own Shorewall-like 
facility).

-Tom
-- 
Tom Eastep    \ Nothing is foolproof to a sufficiently talented fool
Shoreline,     \ http://shorewall.net
Washington USA  \ teastep@shorewall.net




^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: Shorewall vs. Iptables
  2004-02-12 21:56 ` Tom Eastep
@ 2004-02-12 22:17   ` David Cary Hart
  2004-02-12 22:21     ` Tom Eastep
  0 siblings, 1 reply; 4+ messages in thread
From: David Cary Hart @ 2004-02-12 22:17 UTC (permalink / raw)
  To: Tom Eastep; +Cc: Ray Anderson, Netfilter Users' List

[-- Attachment #1: Type: text/plain, Size: 509 bytes --]

On Thu, 2004-02-12 at 16:56, Tom Eastep wrote:

> My opinion is far from unbiased but here goes. Shorewall is a high-level tool 
> for configuring netfilter. It uses the iptables utility to do so. As a 
> result, it cannot offer any more protection than the iptables utility used 
> alone can provide.
> 
Correct me if I am wrong but Shorewall only works properly on a
dedicated box. In other words, if you are running netfilter on the same
machine as a server then Shorewall doesn't work properly.

[-- Attachment #2: This is a digitally signed message part --]
[-- Type: application/pgp-signature, Size: 189 bytes --]

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: Shorewall vs. Iptables
  2004-02-12 22:17   ` David Cary Hart
@ 2004-02-12 22:21     ` Tom Eastep
  0 siblings, 0 replies; 4+ messages in thread
From: Tom Eastep @ 2004-02-12 22:21 UTC (permalink / raw)
  To: David Cary Hart; +Cc: Ray Anderson, Netfilter Users' List

On Thursday 12 February 2004 02:17 pm, David Cary Hart wrote:
> On Thu, 2004-02-12 at 16:56, Tom Eastep wrote:
> > My opinion is far from unbiased but here goes. Shorewall is a high-level
> > tool for configuring netfilter. It uses the iptables utility to do so. As
> > a result, it cannot offer any more protection than the iptables utility
> > used alone can provide.
>
> Correct me if I am wrong but Shorewall only works properly on a
> dedicated box. In other words, if you are running netfilter on the same
> machine as a server then Shorewall doesn't work properly.

You are incorrect.

-Tom
-- 
Tom Eastep    \ Nothing is foolproof to a sufficiently talented fool
Shoreline,     \ http://shorewall.net
Washington USA  \ teastep@shorewall.net




^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2004-02-12 22:21 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2004-02-12 21:32 Shorewall vs. Iptables Ray Anderson
2004-02-12 21:56 ` Tom Eastep
2004-02-12 22:17   ` David Cary Hart
2004-02-12 22:21     ` Tom Eastep

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox