Voder-Vocoder

The Log of Hal Canary

Navigation: Home | THE LOG | Log Archives | Resume | Contact Info | Public Key | SSL | Math Applets | Site Map | WP Backend | RSS2 | Atom

« A310’s suck. | Photography »

Book Review: Linux Firewalls

[book cover]

I’ve been using Ziegler’s Linux Firewalls (2nd Edition) to teach myself iptables syntax. I’m not sure that it’s the best book for getting started building firewalls and routers, bcause it advocates really compliated rulesets.

[]

There are some basic facts about the way iptables works that aren’t explained well. One of them is the diagram on the left. Everyone always draws it funny. The way I draw it, all packes travel downward.

Compare the giant scripts in Ziegler to Rusty’s Really Quick Guide To Packet Filtering

When I was done confguring my router, I had a 61 line iptables script that blocked most ports, did SNAT and DNAT. I didn’t feel the need to, for example, DROP packets on the OUTPUT chain.

Ziegler could use a chapter on troubleshooting with tcpdump and other tools.

Hal Canary | Books | 2004-04-02 15:07:43 EST
Permanent Link | No Comments

Comments are closed.

Copyright 1997-2007 by Hal Canary.
mailto: h3 at halcanary dot org
xmpp:halcanary@jabber.org
aim:halwcanary
http://halcanary.org