From mboxrd@z Thu Jan 1 00:00:00 1970 From: Antony Stone Subject: Re: user defined chains Date: Mon, 12 Jul 2004 21:02:09 +0100 Sender: netfilter-admin@lists.netfilter.org Message-ID: <200407122102.09381.Antony@Soft-Solutions.co.uk> References: <40F2EBB2.7040709@nexusmgmt.com> Reply-To: netfilter Mime-Version: 1.0 Content-Transfer-Encoding: 8bit Return-path: In-Reply-To: <40F2EBB2.7040709@nexusmgmt.com> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" To: netfilter On Monday 12 July 2004 8:51 pm, John A. Sullivan III wrote: > Payal Rathod wrote: > > Hi, > > If I want to design a firewall for a network on a high end machine > > with lot of RAM and swap, is there any real use of user defined > > chains? I find them difficult so I would like to use only the built-in > > chains. Is that ok? > > It may be OK but you will severely limit what you can do. If your > security environment is simple, that will be fine. If it is not, user > defined chains are a real blessing. > > Unless your environment is very simple, it is probably well worth > your time to become very familiar with user defined chains. Despite my somewhat simplistic previous answer, I agree with this also. I guess earlier I should have said "yes, so long as you can do what you need to". Regards, Antony. -- "I estimate there's a world market for about five computers." - Thomas J Watson, Chairman of IBM Please reply to the list; please don't CC me.