Linux Netfilter discussions
 help / color / mirror / Atom feed
* stop/start iptables vs. "iptables-restore"
@ 2007-08-24  0:32 Alex Tang
  2007-08-24 14:46 ` John A. Sullivan III
  2007-08-26 20:24 ` Martijn Lievaart
  0 siblings, 2 replies; 4+ messages in thread
From: Alex Tang @ 2007-08-24  0:32 UTC (permalink / raw)
  To: netfilter

Hi folks,

We run a linux based product (RHEL4 based, kernel-2.6.9-55, and 
iptables-1.2.11). During the running of the product, when we make 
changes to the iptables configuration, we use the SysV-like RHEL script 
"/etc/init.d/iptables restart", which effectively stops iptables, 
unloads all of the iptables based kernel modules, then starts iptables 
and all the kernel stuff. 

A colleague recently asked why we're not using "iptables-restore" 
instead of the script which does "stop/start".  I'm looking to see if 
you know of any reasons why we should or should not use iptables-restore 
vs. "stop/start".  Does it matter if the number of connections on the 
system is high?  Our product can sometimes handle many millions of 
connections per day.

Thanks.

...alex...



^ permalink raw reply	[flat|nested] 4+ messages in thread
[parent not found: <200708251004.l7PA4Q5a008128@mail3.jubileegroup.co.uk>]

end of thread, other threads:[~2007-08-26 20:24 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2007-08-24  0:32 stop/start iptables vs. "iptables-restore" Alex Tang
2007-08-24 14:46 ` John A. Sullivan III
2007-08-26 20:24 ` Martijn Lievaart
     [not found] <200708251004.l7PA4Q5a008128@mail3.jubileegroup.co.uk>
2007-08-25 22:11 ` G.W. Haywood

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox