Re: tcpsvd vs. tcpserver

Vincent Danen <[email protected]>
Newsgroups gmane.comp.misc.pape.general
Message-ID <[email protected]>
On 5-Oct-04, at 8:30 AM, Charlie Brady wrote:

>>> Yes, except for the -X option, and that the cdbs are not compatible,
>>> you
>>> can't use a cdb created with tcprules with ipsvd(7), you would need 
>>> to
>>> create a new one using ipsvd-cdb(8), or use the directory directly.
>>
>> I think using the directory makes more sense since the directory needs
>> to exist anyways (I can see it being different for a large directory
>> with a lot of rules, but I think by and large the directory method
>> would be the simplest).
>
> I've recently done some conversion, and found the directory method 
> simple
> and clear. Unless you have a heavily pounded server, I doubt you'd 
> notice
> any performace difference.

That's kinda what I thought as well.

> What I've found useful is to generate one config file for each policy I
> wish to implement (in my case, only "local" and "default"), and 
> generate
> a set of symlinks for each network specification, viz: 0 -> default,
> 192.168.1 -> local, 127.0.0.1 -> local, 10.39.155 -> local. [This 
> approach
> is perfect for me, since I generate all my config from a db of service
> policies and network lists; it may be less useful if you expect a 
> human to
> construct the files and symlinks.]

Interesting idea, and one that may come in useful when I write a web 
interface to configure this stuff.

-- 
Annvix - Secure Linux Server: http://annvix.org/
*Please note gpg keyid FE6F2AFD has been replaced with keyid FEE30AD4*
"lynx -source http://linsec.ca/vdanen.asc | gpg --import"
{FEE30AD4 : 7F6C A60C 06C2 4811 FA1C  A2BC 2EBC 5E32 FEE3 0AD4}
PGP.sig (application/pgp-signature, 186 B) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.