On 3/19/06, Ravi Kumar <[EMAIL PROTECTED]> wrote: > > Hello sanjay, > I have a few questions regarding ipcop. Since you have been using > it, and while we are on this subject, I hope it is fair to ask you > about it. > can ipcop and iptables run simultaneously on ones machine? or do I > have to uninstall iptables prior to installing ipcop? And what are the > advantages of using ipcop over iptables ? Does ipcop use iptables in > the backend or is it an entirely different implementation ? I have > been using iptables till now. Is configuring ipcop more easier than > iptables? > Ravi
IPcop is a small firewall distro that uses iptables for firewalling. It is a minimal distro with a philosopy that the firewall machine should not be running applications. It requires a dedicated machine, though you can use any old machine for it...I have heard of people using 486 or PIs. It has a GUI based configuration for IPtables and has snort & squid built-in, for IDS. Logs too are beautifuly shown in GUI. Also built in is a ipsec vpn & provides NAT and DMZ, all gui configurable with minimal or no iptables knowledge. For a soho configurations, I think it is a very good solution, unless you require load-balanced multiple internet connections. There are a variety of add-ons available in the community, though not supported by the main ipcop team. These range from small issues from blocking outward traffic (IPcop default install blocks only incoming connections & allows outgoing & established connections) to http content filtering etc. I hope that soon we will see ipcop installed as a Xen virtual machine, doing away with the need of requiring seperate machine, which is not a major problem as most people use an old machine for it. In three years of using IPcop, I have not had a single successful breakin attempt, whereas there were three in one year before I started using it...and I cannot use IPtables directly...never bothered to learn...I did just fine with IPcop. Do visit www.ipcop.org and also look for links to ipcop add-ons...there are two seperate websites catering to them and links are there in IPcop.org. With regards. Sanjay. ------------------------------------------------------- This SF.Net email is sponsored by xPML, a groundbreaking scripting language that extends applications into web and mobile media. Attend the live webcast and join the prime developer group breaking into this new coding territory! http://sel.as-us.falkag.net/sel?cmd=lnk&kid0944&bid$1720&dat1642 _______________________________________________ linux-india-help mailing list linux-india-help@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/linux-india-help