Re: [rock-user] Firewall Rules and System Startup

Bernd Petrovitsch <[email protected]> Sun, 06 Nov 2005 19:53:47 +0100
Newsgroups gmane.linux.distributions.rock.user
Organization http://www.firmix.at/
Message-ID <[email protected]>
On Sun, 2005-11-06 at 19:43 +0100, Benjamin Schieder wrote:
[...]
> Bernd Petrovitsch wrote:
> > How and where is one supposed to put the firewall rules into?
> > 
> > In theory I want:
> > 1) configure interfaces, but do not `ip set link eth<x> up` them.
> > 2) possibly add and/or delete routes
> > 3) add firewall rules
> > 4) ip set link eth<x> up
> > 
> > 1) is configured with stone and started somewhere and somehow.
> > And 2)-4)?
> 
> Theres rudimentary support for 3) in /etc/network/modules/iptables.sh

Hmm, that's by far too less. I think I will stick with my self-written
script full of `iptables` calls.

> For 2) there's only a 'default route' possibility in yet.
> 4) is done automatically when adding the interface.

Yes, that's the problem.

While I'm on it: I have an openvpn tunnel. Do I configure the thing in
stone as a normale device (with name tap1) and how?

	Bernd
-- 
Firmix Software GmbH                   http://www.firmix.at/
mobil: +43 664 4416156                 fax: +43 1 7890849-55
          Embedded Linux Development and Services