From mboxrd@z Thu Jan 1 00:00:00 1970 From: Tom Eastep Subject: Re: Shorewall vs. Iptables Date: Thu, 12 Feb 2004 14:21:02 -0800 Sender: netfilter-admin@lists.netfilter.org Message-ID: <200402121421.02858.teastep@shorewall.net> References: <004201c3f1af$b16d7fa0$2405010a@rsa> <200402121356.56294.teastep@shorewall.net> <1076624237.3037.26.camel@dchws.TQMcube.com> Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: <1076624237.3037.26.camel@dchws.TQMcube.com> Content-Disposition: inline Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" To: David Cary Hart Cc: Ray Anderson , Netfilter Users' List On Thursday 12 February 2004 02:17 pm, David Cary Hart wrote: > On Thu, 2004-02-12 at 16:56, Tom Eastep wrote: > > My opinion is far from unbiased but here goes. Shorewall is a high-level > > tool for configuring netfilter. It uses the iptables utility to do so. As > > a result, it cannot offer any more protection than the iptables utility > > used alone can provide. > > Correct me if I am wrong but Shorewall only works properly on a > dedicated box. In other words, if you are running netfilter on the same > machine as a server then Shorewall doesn't work properly. You are incorrect. -Tom -- Tom Eastep \ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ teastep@shorewall.net