LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-02-2005, 10:10 AM   #1
syeronne
LQ Newbie
 
Registered: Nov 2005
Posts: 15

Rep: Reputation: 0
Newbie question about iptables/shorewall


Hi,

I'm using a Mandriva 2006 edition and I have bot iptables and shorewall installed.
I was wondering what's the difference between them ? Can i use shorewall w/o iptables and vice-versa ?
How are they related to Netfilter ?
Both of them are installed in services : shall I turn them on at startup ?

Thanks in advance.
 
Old 12-02-2005, 11:58 AM   #2
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,659
Blog Entries: 4

Rep: Reputation: 3939Reputation: 3939Reputation: 3939Reputation: 3939Reputation: 3939Reputation: 3939Reputation: 3939Reputation: 3939Reputation: 3939Reputation: 3939Reputation: 3939
The actual low-level mechanism that the kernel uses to filter packets is "iptables." (There was an older version called "ipchains" that isn't used anymore.)

Products like ShoreWall are simply power-tools for quickly building appropriate sets of iptables rules. The mechanisms provided by Linux are fairly cryptic, and products like Shorewall make setting up the desired configuration much easier. (Furthermore, the resulting firewall will be a lot "smarter," since very-experienced people set up those rules files so that the rest of us can simply benefit from their expertise.)

Note: If you have both a service named iptables and a service named shorewall enabled at the same time, you probably don't want/need to do that. You'll find that both of them build and issue iptables-rules, and you do not want them to conflict, because in doing so they might weaken or screw-up your firewall. Choose one or the other; I suggest shorewall.

Last edited by sundialsvcs; 12-02-2005 at 12:00 PM.
 
Old 12-02-2005, 04:08 PM   #3
syeronne
LQ Newbie
 
Registered: Nov 2005
Posts: 15

Original Poster
Rep: Reputation: 0
You said that the low-level mechanism that the kernel uses is iptables but suggest to use shorewall instead ! There's something I don't understand...

Last edited by syeronne; 12-05-2005 at 04:24 AM.
 
Old 12-05-2005, 04:25 AM   #4
syeronne
LQ Newbie
 
Registered: Nov 2005
Posts: 15

Original Poster
Rep: Reputation: 0
Any reply ?
 
Old 12-05-2005, 04:18 PM   #5
taiwf
Member
 
Registered: Jun 2005
Distribution: debian, ubuntu, redhat,knoppix
Posts: 194

Rep: Reputation: 31
i never use shorewall, but according to sundailsvc , shorewall just a tool for ease of using iptables. It itself isn't provide much (if any) protection. Its like you can use note pad and frontpage to write html, only later ones is much easier.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
shorewall config question with /etc/shorewall/rules peter72 Linux - Networking 3 01-01-2007 09:33 PM
Newbie iptables INPUT question new@linux Linux - Security 6 03-08-2005 10:42 AM
iptables newbie question Beauford-2 Linux - Security 4 09-26-2004 04:41 AM
iptables newbie question TurtleBay Linux - Newbie 10 10-09-2003 02:37 PM
Newbie Question - IPTables cyberperson Linux - Networking 1 03-14-2003 10:22 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:06 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration