Marcel,

Great, thanks!  I'm also very willing to help.  The patches I use are:

ipt_time: Great shutting off internet access for the kids after 10pm or 
something
ipt_string: Matches strings within packet payloads
ipt_psd: Portscan detector, very nice
ipt_nth: match every nth packet
ipt_iplimit: you know about that one, quite useful
ipt_recent: make a temporary bad-guy rule for someone who 'recently', say, 
triggered the portscan detector
ip_conntrack_pptp and ip_nat_pptp: for allowing vpn connections from/through 
the firewall machine (I don't think these are part of patch-o-matic)

Thanks!

Rocco

On Saturday 14 December 2002 04:20 am, Marcel Pol spake thusly:
> Which patches are the usefull ones over there? I haven't looked much there,
> just at string and iplimit, and iplimit seems interesting.
> Which ones do you use, and would you recommend? Most of that stuff doesn't
> change much, and shouldn't be that hard to make a patch of that patches
> into the mdk-kernel. I'd be willing to help wth that.


Reply via email to