Re: what comes after firehol?
Phil Whineray <[email protected]>
| Newsgroups | gmane.comp.security.firewalls.firehol.user |
|---|---|
| Message-ID | <BANLkTinVxdK6vqN_jeCbNCYyjD8Z7RGa3hbQmStGCOFJGV3JhA@mail.gmail.com> |
On 12 June 2011 12:45, Klaus Kruse <[email protected]> wrote: > Am 12.06.2011 13:27, schrieb Harry Sufehmi: >> On 6/12/11, John Dalton <[email protected]> wrote: >>> The lack of releases hasn't bothered me - it's stable and mature, and >>> one of the first things I install on every host. >> Absolutely agree. >> >> I've yet to find another firewall product that's : >> >> 1. Very accessible & easy to maintain over a SLOW ssh connection >> 2. Very easy to use, yet >> 3. Very versatile, and >> 4. Very stable & dependable >> 5. Almost zero dependency - it doesn't require you to install this >> library & that library & apache & php & etc. Just bash & iptables. >> >> firehol is a rarity in the software world. Not many other software is >> able to achieve even point 2 to 4. > You all are absolutely right, firehol is small, flexible and (most > important!) super-easy to use. I'm just a student of sociology and have > no deep knowledge of networking. But with firehol, configuring a > three-network-interfaces homeserver with a lot of services just...works. > > I would really like to see IPv6-support, as this will become important. > Just this and I'll be happy for the next decade :) A while back I created a git repository which adds IPv6 support. If you: git clone git://repo.or.cz/fireholvi You can try a version with mixed IPv4/IPv6 support. I suggest checking the rules output by hand before using them in production but it fullfills all my needs. There's also a cvs-mirror branch which tracks the official CVS repo if that's useful to anyone. Regards Phil ------------------------------------------------------------------------------ EditLive Enterprise is the world's most technically advanced content authoring tool. Experience the power of Track Changes, Inline Image Editing and ensure content is compliant with Accessibility Checking. http://p.sf.net/sfu/ephox-dev2dev