iptables-restore

green <[email protected]>
Newsgroups gmane.linux.debian.devel.firewall
Message-ID <20100620140703.GA5176@swansys>
I am working on setting up a firewall on a server/router (see 
http://wiki.debian.org/green/Router ).  I have considered several different 
firewall packages, but am more comfortable just running iptables in a shell 
script.

However, iptables scripts usually begin with a flush, and then it takes time to 
add all those rules, plus some possible interruption to traffic meanwhile.  
What about if only a small change has been made?  Does iptables-restore flush 
first, or is it able to just change the rule set as necessary to match?  (And 
is there a term used to describe that feature?)

If iptables-restore does not support that, does anyone know of another tool 
(available the repositories) that I can use that would allow me to write a 
parseable iptables rule set?

Thanks.
signature.asc (application/pgp-signature, 198 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAkweIIcACgkQ682C+dBP+oTEFgCg6j/CQZT+nVBUhAQNv+f6XMJh
VDQAoI4fn76dWdX3xwp4QPye6MYQ2rWP
=l6PF
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.