Re: [rock-user] Firewall Rules and System Startup

Clifford Wolf <[email protected]> Mon, 7 Nov 2005 17:49:12 +0100
Newsgroups gmane.linux.distributions.rock.user
Message-ID <[email protected]>
Hi,

On Mon, Nov 07, 2005 at 10:02:35AM +0100, Andreas V. Meier wrote:
> > Hmm, that's by far too less. I think I will stick with my self-written
> > script full of `iptables` calls.
>
> There is a hook called run-up, which executes a script at interface setup time.
> [..]

If you want to use rocknet for that and the commands from the iptables
module are not sufficient, you can use the keywords defined in
/etc/network/modules/script.sh to link in your scripts.

On systems with really complex network configs (with various tunnels,
brigding, ebtables and/or complex iptables rules, etc. etc.) I simply write
my own init script and don't start the 'network' service at all.

yours,
 - clifford

-- 
L I N : B I T           ___
 _______ __ _____  ____|_  |  The OSS cluster synchronization tool for
/ __(_-</ // / _ \/ __/ __/   configuration files an application images
\__/___/\_, /_//_/\__/____/   --- [ http://oss.linbit.com/csync2/ ] ---
       /___/
 
The number of the beast - vi vi vi.