William Kenworthy <bi...@iinet.net.au> wrote: > > If you are going to go to this bother ... why not use shorewall, create
When I checked for scripts creating rules, none fulfilled my needs. (I do not know whether I checked shorewall at this time). For instance, instead of dropping most packets, I want to reject them properly, only with a rate-limit to avoid DOS. Then there is the mentioned port knocking, some forwarding etc. pp. > a custom configuration for each site (including any changes to services) > and and have your script just copy them in and restart the various > services including shorewall? Instead of managing dozens of configurations manually, I think it is easier to have one script which creates an appropriate custom configuration on all my machines, depending on certain files in /etc and other tests. That's why I always run my firewall script on startup (or if I severely change the configuration). > I use a simple script with autosetup using network-manager network-manager is on my university's laptop (with Ubuntu - not my decision), but on any "safe" machine (running Gentoo) I refuse to install the gaping security hole "polkit" which unfortunately is a hard dependency of network-manager. As soon as "polkit" is on an machine on which you use a browser, it makes no sense to spend time pretending to make it secure: Barring your back door even more when the front door of your house was removed is rather pointless...