Re: iptables: "stateful inspection?"

From: Michael H. Warfield (mhw@wittsend.com)
Date: Wed Dec 20 2000 - 11:25:02 EST


On Wed, Dec 20, 2000 at 11:18:10AM -0500, Michael Rothwell wrote:
> IPChains is essentially useless as a firewall due to its lack of

        I think that's more than a little overstatement on your
part. It depends entirely on the application you intend to put
it to. It may be entirely useless TO YOU and your applications,
but your statement is far to broad to be accurate.

> stateful packet filering. Will the IPTables code in 2.4 maintain
> connection state?

        Yes it does. It's clearly stated in all the documentation
on netfilter and in it's design. Read the fine manual (or web site)
and you would have uncovered this (or been run over by it) for yourself.

        http://netfilter.filewatcher.org/

> -M

        Mike

-- 
 Michael H. Warfield    |  (770) 985-6132   |  mhw@WittsEnd.com
  (The Mad Wizard)      |  (678) 463-0932   |  http://www.wittsend.com/mhw/
  NIC whois:  MHW9      |  An optimist believes we live in the best of all
 PGP Key: 0xDF1DD471    |  possible worlds.  A pessimist is sure of it!

- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org Please read the FAQ at http://www.tux.org/lkml/



This archive was generated by hypermail 2b29 : Sat Dec 23 2000 - 21:00:27 EST