* Shorewall vs. Iptables
@ 2004-02-12 21:32 Ray Anderson
2004-02-12 21:56 ` Tom Eastep
0 siblings, 1 reply; 4+ messages in thread
From: Ray Anderson @ 2004-02-12 21:32 UTC (permalink / raw)
To: netfilter
Is any one better than the other?
I'm currently running a RedHat box that's soon to be replaced with a
Mandrake machine. Of course I threw out the Shorewall stuff in favor of
manually implementing the same Iptables ruleset(s) that I have for the RH
machine.
Does Shorewall give any more protection or is it a simply complicated
front-end to iptables?
Cheers,
-=Ray
---------------------------------------
When reaching a stalemate, win with a technique the enemy does not expect.
Miyamoto Musashi
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: Shorewall vs. Iptables
2004-02-12 21:32 Shorewall vs. Iptables Ray Anderson
@ 2004-02-12 21:56 ` Tom Eastep
2004-02-12 22:17 ` David Cary Hart
0 siblings, 1 reply; 4+ messages in thread
From: Tom Eastep @ 2004-02-12 21:56 UTC (permalink / raw)
To: Ray Anderson, netfilter
On Thursday 12 February 2004 01:32 pm, Ray Anderson wrote:
> Is any one better than the other?
>
> I'm currently running a RedHat box that's soon to be replaced with a
> Mandrake machine. Of course I threw out the Shorewall stuff in favor of
> manually implementing the same Iptables ruleset(s) that I have for the RH
> machine.
Who wouldn't? :-)
Actually, I recommend against using the Mandrake Shorewall two-interface
configuration.
a) it matches my documentation enough that cutting and pasting from the
documentation doesn't produce errors; but
b) it is different enough that the such cutting and pasting doesn't produce
the desired results.
>
> Does Shorewall give any more protection or is it a simply complicated
> front-end to iptables?
My opinion is far from unbiased but here goes. Shorewall is a high-level tool
for configuring netfilter. It uses the iptables utility to do so. As a
result, it cannot offer any more protection than the iptables utility used
alone can provide.
As for being complicated, if you already understand iptables then Shorewall
would be something else to learn. If you don't, then most people find
Shorewall easier to learn. I definitely believe it to be easier to set up
complex router/firewall configurations using Shorewall than it is using
iptables directly unless you have spent a long time developing your own very
flexible firewall/router framework (in other words, your own Shorewall-like
facility).
-Tom
--
Tom Eastep \ Nothing is foolproof to a sufficiently talented fool
Shoreline, \ http://shorewall.net
Washington USA \ teastep@shorewall.net
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: Shorewall vs. Iptables
2004-02-12 21:56 ` Tom Eastep
@ 2004-02-12 22:17 ` David Cary Hart
2004-02-12 22:21 ` Tom Eastep
0 siblings, 1 reply; 4+ messages in thread
From: David Cary Hart @ 2004-02-12 22:17 UTC (permalink / raw)
To: Tom Eastep; +Cc: Ray Anderson, Netfilter Users' List
[-- Attachment #1: Type: text/plain, Size: 509 bytes --]
On Thu, 2004-02-12 at 16:56, Tom Eastep wrote:
> My opinion is far from unbiased but here goes. Shorewall is a high-level tool
> for configuring netfilter. It uses the iptables utility to do so. As a
> result, it cannot offer any more protection than the iptables utility used
> alone can provide.
>
Correct me if I am wrong but Shorewall only works properly on a
dedicated box. In other words, if you are running netfilter on the same
machine as a server then Shorewall doesn't work properly.
[-- Attachment #2: This is a digitally signed message part --]
[-- Type: application/pgp-signature, Size: 189 bytes --]
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: Shorewall vs. Iptables
2004-02-12 22:17 ` David Cary Hart
@ 2004-02-12 22:21 ` Tom Eastep
0 siblings, 0 replies; 4+ messages in thread
From: Tom Eastep @ 2004-02-12 22:21 UTC (permalink / raw)
To: David Cary Hart; +Cc: Ray Anderson, Netfilter Users' List
On Thursday 12 February 2004 02:17 pm, David Cary Hart wrote:
> On Thu, 2004-02-12 at 16:56, Tom Eastep wrote:
> > My opinion is far from unbiased but here goes. Shorewall is a high-level
> > tool for configuring netfilter. It uses the iptables utility to do so. As
> > a result, it cannot offer any more protection than the iptables utility
> > used alone can provide.
>
> Correct me if I am wrong but Shorewall only works properly on a
> dedicated box. In other words, if you are running netfilter on the same
> machine as a server then Shorewall doesn't work properly.
You are incorrect.
-Tom
--
Tom Eastep \ Nothing is foolproof to a sufficiently talented fool
Shoreline, \ http://shorewall.net
Washington USA \ teastep@shorewall.net
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2004-02-12 22:21 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2004-02-12 21:32 Shorewall vs. Iptables Ray Anderson
2004-02-12 21:56 ` Tom Eastep
2004-02-12 22:17 ` David Cary Hart
2004-02-12 22:21 ` Tom Eastep
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox