You are not logged in.

#1 2008-05-30 11:56:07

foxbunny
Member
From: Serbia
Registered: 2006-10-31
Posts: 759
Website

Shorewall vs straight iptables?

I've set up my gateway's fw using Shorewall. It was really simple, and I'm quite happy with it (although I haven't tested it yet).

Next thing I wanted to know is:

Does configuring the firewall using iptables directly have any advantages over Shorewall, and is the learning curve worth it? Or IOW, is there anything Shorewall cannot handle that iptables can?

Offline

#2 2008-05-30 12:30:32

pluisje
Member
From: 127.0.0.1
Registered: 2008-05-20
Posts: 5

Re: Shorewall vs straight iptables?

shorewall is indeed really simple but its just an frontend for iptables...
i think should know what your firewall is doing, learning iptables is always handy..
for example if you want to open an port for testing software or so

the advantage of iptables over shorewall is you know what your firewall works...

Offline

#3 2008-05-30 15:32:10

Redroar
Member
Registered: 2008-03-17
Posts: 200

Re: Shorewall vs straight iptables?

Well, using iptables --list lets you check if shorewalls script is doing it's job. But then again, you need to know iptables to really understand the output of iptables --list.

Iptables isn't that hard if you have the right guide....the problem is that most guides have waaaaaay more information than you need, and it's hard to find the simple stuff. The ArchWiki "Simple Stateful Firewall" guide should get you going, and once you understand the logic it's not hard.


Stop looking at my signature. It betrays your nature.

Offline

#4 2008-05-30 15:58:10

foxbunny
Member
From: Serbia
Registered: 2006-10-31
Posts: 759
Website

Re: Shorewall vs straight iptables?

I will definitely invest time in understanding iptables. But I wanted to know if there are any benefits over Shorewall in production use (like more secure, more flexible, etc etc). I'm asking, because I'm preparing myself for VPS maintenance, and I find Shorewall super-fast for deployment.

Offline

Board footer

Powered by FluxBB