William Kenworthy <bi...@iinet.net.au> wrote:
>
> If you are going to go to this bother ... why not use shorewall, create

When I checked for scripts creating rules, none fulfilled my needs.
(I do not know whether I checked shorewall at this time).
For instance, instead of dropping most packets, I want to reject them
properly, only with a rate-limit to avoid DOS. Then there is the
mentioned port knocking, some forwarding etc. pp.

> a custom configuration for each site (including any changes to services)
> and and have your script just copy them in and restart the various
> services including shorewall?

Instead of managing dozens of configurations manually,
I think it is easier to have one script which creates an
appropriate custom configuration on all my machines, depending
on certain files in /etc and other tests. That's why I always
run my firewall script on startup (or if I severely change
the configuration).

> I use a simple script with autosetup using network-manager

network-manager is on my university's laptop (with Ubuntu -
not my decision), but on any "safe" machine (running Gentoo)
I refuse to install the gaping security hole "polkit"
which unfortunately is a hard dependency of network-manager.
As soon as "polkit" is on an machine on which you use a browser,
it makes no sense to spend time pretending to make it secure:
Barring your back door even more when the front door of your house
was removed is rather pointless...


Reply via email to