iptables-restore
green <[email protected]>
| Newsgroups | gmane.linux.debian.devel.firewall |
|---|---|
| Message-ID | <20100620140703.GA5176@swansys> |
I am working on setting up a firewall on a server/router (see http://wiki.debian.org/green/Router ). I have considered several different firewall packages, but am more comfortable just running iptables in a shell script. However, iptables scripts usually begin with a flush, and then it takes time to add all those rules, plus some possible interruption to traffic meanwhile. What about if only a small change has been made? Does iptables-restore flush first, or is it able to just change the rule set as necessary to match? (And is there a term used to describe that feature?) If iptables-restore does not support that, does anyone know of another tool (available the repositories) that I can use that would allow me to write a parseable iptables rule set? Thanks.
signature.asc
(application/pgp-signature, 198 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iEYEARECAAYFAkweIIcACgkQ682C+dBP+oTEFgCg6j/CQZT+nVBUhAQNv+f6XMJh VDQAoI4fn76dWdX3xwp4QPye6MYQ2rWP =l6PF -----END PGP SIGNATURE-----