On 9/16/10 3:07 PM, Steven Jan Springl wrote:
> Tom
> 
> Would it be possible/practical to implement blacklisting using ipset, if it 
> is 
> available.
> This should enable people to have a large number of entries in their 
> blacklist 
> without causing performance issues.

Steven,

It's already supported. Just put +<ipset name> in the first column.

Regards,
-Tom
-- 
Tom Eastep        \ When I die, I want to go like my Grandfather who
Shoreline,         \ died peacefully in his sleep. Not screaming like
Washington, USA     \ all of the passengers in his car
http://shorewall.net \________________________________________________

Attachment: signature.asc
Description: OpenPGP digital signature

------------------------------------------------------------------------------
Start uncovering the many advantages of virtual appliances
and start using them to simplify application deployment and
accelerate your shift to cloud computing.
http://p.sf.net/sfu/novell-sfdev2dev
_______________________________________________
Shorewall-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-devel

Reply via email to