LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Other *NIX Forums > *BSD
User Name
Password
*BSD This forum is for the discussion of all BSD variants.
FreeBSD, OpenBSD, NetBSD, etc.

Notices


Reply
  Search this Thread
Old 01-31-2005, 07:56 AM   #1
xround
Member
 
Registered: Oct 2003
Location: France
Distribution: RH9
Posts: 84

Rep: Reputation: 15
using ipfw on a linux release ?


Hello, I don't know much about this so here is the question.
Is it possible to install firewall ipfw on a linux (kernel 2.4.27) version.
I have been advised to install this firewall.
Can I do that?
Will I have to uninstall iptables ?

Thanks, Xround
 
Old 01-31-2005, 09:12 AM   #2
nixcraft
Member
 
Registered: Nov 2004
Location: BIOS
Distribution: RHEL3.0, FreeBSD 5.x, Debian 3.x, Soaris x86 v10
Posts: 379

Rep: Reputation: 30
IPFW was 1st Generation Alan Cox's port of BSD UNIX's ipfw firewall to Linux 1.1 kernel.

You don't need to install this on Linux we have iptables - 4th Generation ~ Rusty Russel and others implemented a modular packet filter/mangler firewallLinux 2.4/2.6 kernels use this and you don't need to use ipfw on linux.

ipfw == BSD firewall
iptables == Linux firewall
 
Old 02-10-2005, 02:46 AM   #3
xround
Member
 
Registered: Oct 2003
Location: France
Distribution: RH9
Posts: 84

Original Poster
Rep: Reputation: 15
Thank you for your answer. I was on holiday so I did not read much on internet since a week.

The reason for the question of installing ipfw on linux, is that I have problems with iptables, concerning large list to ban. Iptables is long to load large lists (I have around 10000 adress to be banned, and doing a ip-restore with iptables uses 7 or 8 hours ! ) and cause some problems with network ( restarting network service freezes or stops or is too long while lo "restart" ).

The advise come from a guy that may ban these address via ipfw and that has not these problems. Has anyone heard about this ?

Thanks, xround.
 
Old 02-10-2005, 03:02 AM   #4
okmyx
Member
 
Registered: May 2004
Location: Cornwall, UK
Distribution: Ubuntu 8.04
Posts: 464

Rep: Reputation: 31
Couldn't you use an iptables firewall to protect your computer and a proxy server to block the 10000 sites?
 
Old 02-10-2005, 12:44 PM   #5
sigsegv
Senior Member
 
Registered: Nov 2004
Location: Third rock from the Sun
Distribution: NetBSD-2, FreeBSD-5.4, OpenBSD-3.[67], RHEL[34], OSX 10.4.1
Posts: 1,197

Rep: Reputation: 47
Also, the (likely) reason it's taking so long is because of DNS lookups. Are you DENYing sites by IP or name? If you're doing it by name, that's the problem.

okmyx is correct though. Setting a list of sites that your users are not allowed to connect to with iptables isn't the worst possible way to do it, but it's close... Investigate squid or something similar.
 
Old 02-12-2005, 03:26 PM   #6
newpenguin
Member
 
Registered: Sep 2002
Location: lahore pakistan
Distribution: slackware,redhat, FreeBSD,openbsd
Posts: 219

Rep: Reputation: 30
once i did the same thing with packet filter.
my table was storing many addresses in domain name form, it also used to took an hour whenever i reload them.
 
Old 02-18-2005, 05:39 AM   #7
xround
Member
 
Registered: Oct 2003
Location: France
Distribution: RH9
Posts: 84

Original Poster
Rep: Reputation: 15
I don't use dns name, only ip addresses? However, I thought ipfw was ok to manage large ip list. I will try with a proxy.
Thanks, xround.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
SUSE Release 10 RC1 Release Candidate 1 available 1kyle SUSE / openSUSE 8 09-11-2005 06:26 PM
IPFW rules ryancoolest *BSD 5 02-19-2004 01:03 AM
Linux Release Date codedv Linux - General 1 12-16-2003 05:58 AM
What is the best Linux release? tommilaiho Linux - Distributions 4 11-11-2003 02:21 AM
Linux DON'T know how to release RAM? raylpc Linux - General 2 07-16-2003 07:25 AM

LinuxQuestions.org > Forums > Other *NIX Forums > *BSD

All times are GMT -5. The time now is 12:38 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration