Linux Netfilter discussions
 help / color / mirror / Atom feed
* safely apply new rulesets: iptables-apply
@ 2008-03-04 23:16 martin f krafft
  2008-03-05 10:37 ` Maximilian Wilhelm
  2008-03-09 16:45 ` safely apply new rulesets: iptables-apply Jan Engelhardt
  0 siblings, 2 replies; 19+ messages in thread
From: martin f krafft @ 2008-03-04 23:16 UTC (permalink / raw)
  To: netfilter discussion list

[-- Attachment #1: Type: text/plain, Size: 1117 bytes --]

Hi folks,

You probably now the feeling, that cold and hot rush of adrenaline
after you've typed "iptables-restore < new-ruleset" and didn't get to
see the shell prompt again: you've just locked yourself out of
a machine that’s potentially far away, and you feel like vandalism,
or screaming on the top of your lungs, or whatever.

I've had that feelings once too many and ended up writing
iptables-apply[0] with a docbook manpage[1].

0. http://svn.madduck.net/pub/sbin/base/iptables-apply
1. http://svn.madduck.net/pub/sbin/base/iptables-apply.dbk

iptables-apply is a simple shell script which applies the new
ruleset and then prompts whether you like it. If you've locked
yourself out, you cannot answer the prompt, and if you don't, the
script rolls back the ruleset. Nice and simple.

Could this script possibly make it into the iptables distribution
tarball? I am flexible about the licence and all...

Thanks,

-- 
martin | http://madduck.net/ | http://two.sentenc.es/
 
perl -e 'print "The earth is a disk!\n" if ( "earth" == "flat" );'
 
spamtraps: madduck.bogus@madduck.net

[-- Attachment #2: Digital signature (see http://martin-krafft.net/gpg/) --]
[-- Type: application/pgp-signature, Size: 189 bytes --]

^ permalink raw reply	[flat|nested] 19+ messages in thread

end of thread, other threads:[~2008-04-17 10:12 UTC | newest]

Thread overview: 19+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2008-03-04 23:16 safely apply new rulesets: iptables-apply martin f krafft
2008-03-05 10:37 ` Maximilian Wilhelm
2008-03-05 11:42   ` martin f krafft
2008-03-05 11:46     ` martin f krafft
2008-03-05 11:56       ` 'queue' on 64-bit Scott MacKay
2008-03-05 12:59         ` martin f krafft
2008-03-09 16:45 ` safely apply new rulesets: iptables-apply Jan Engelhardt
2008-03-10 11:02   ` martin f krafft
2008-03-11 18:54     ` Jan Engelhardt
2008-03-11 19:00       ` martin f krafft
2008-03-11 19:30         ` Jan Engelhardt
2008-03-11 20:29           ` martin f krafft
2008-04-04  6:32             ` martin f krafft
2008-04-10 10:29               ` Jan Engelhardt
2008-04-10 13:34                 ` martin f krafft
2008-04-10 13:44                   ` martin f krafft
2008-04-16 21:56       ` Martijn Lievaart
2008-04-17  8:05         ` martin f krafft
2008-04-17 10:12           ` Покотиленко Костик

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox