Re: Correct way to transfer V1.4 rules to V2.0?

"Steve" <[email protected]>
Newsgroups gmane.comp.security.ipcop.devel
Message-ID <4E7EF3D6.000003.04440@STEVEPC>
 

Ah. So not a few rules for a handful of machines on a single ipcop then!

 

 

 

-------Original Message------- 

 

From: John Edwards 

Date: 25/09/2011 10:09:58 

To: Steve 

Cc: IPCOP devel 

Subject: Re: [IPCop-devel] Correct way to transfer V1.4 rules to V2.0? 

 

On Sun, Sep 25, 2011 at 09:33:29AM +0100, Steve wrote: 

> 

> Cant be that hard to print them and re enter ? 

 

May be not hard, but time consuming, boring, and very likely to 

introduce mistakes. 

 

I've had firewalls with over 50 rules for port forwarding (about 

10 port forwards for 5+ machines). If you then include access 

restrictions for each of those you easily get 100s per firewall. 

 

We look after about 15 firewalls, so that is potentially 1000s of 

rules to enter. Entering those manually will mean mistakes. 

 

Dealing with boring and time consuming data transformation is an 

excellent job for a computer. A simple sed or awk script should 

able to transform a comma separated file format. 

 

 

-- 

#---------------------------------------------------------# 

| John Edwards Email: john-C/[email protected] | 

#---------------------------------------------------------# 

 

------------------------------------------------------------------------------
All of the data generated in your IT infrastructure is seriously valuable.
Why? It contains a definitive record of application performance, security
threats, fraudulent activity, and more. Splunk takes this data and makes
sense of it. IT sense. And common sense.
http://p.sf.net/sfu/splunk-d2dcopy2
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.