Re: stateful inspection firewall

From: Cedric Blancher (blancher_at_cartel-securite.fr)
Date: 10/27/03


Date: Mon, 27 Oct 2003 17:12:09 +0100

Dans sa prose, Dario nous ecrivait :
> Does anybody know if the IPTables firewalling subsystem is a real stateful
> inspection one, like OpenBSD Packet Filter or Cisco PIX, or it is just a
> connection tracking firewall which just checks for connection ports and IP
> addresses?

Netfilter does not track TCP window such as pf. However, you can add this
feature using a patch distributed with iptables patch-o-matic.

> Is it somewhere available a recent and updated comparison in
> performance and feutures between IPTables and Packet Filter?

Dunno, but very interested ;)

-- 
 Lu sur alt.france :
 Peut-on installer Win 95 par dessus win 95 tout en gardant les
 differents données des logiciels fonctionnant auparavant sur wwin 95 ?
 -+- JMT in : Guide du neuneu d'Usenet - Neuneu persiste et signe -+-


Relevant Pages

  • Re: stateful inspection firewall
    ... > Does anybody know if the IPTables firewalling subsystem is a real stateful ... feature using a patch distributed with iptables patch-o-matic. ... > performance and feutures between IPTables and Packet Filter? ... differents données des logiciels fonctionnant auparavant sur wwin 95? ...
    (comp.unix.bsd.freebsd.misc)
  • Re: stateful inspection firewall
    ... > Does anybody know if the IPTables firewalling subsystem is a real stateful ... feature using a patch distributed with iptables patch-o-matic. ... > performance and feutures between IPTables and Packet Filter? ... differents données des logiciels fonctionnant auparavant sur wwin 95? ...
    (comp.unix.bsd.openbsd.misc)
  • Re: stateful inspection firewall
    ... > Does anybody know if the IPTables firewalling subsystem is a real stateful ... feature using a patch distributed with iptables patch-o-matic. ... > performance and feutures between IPTables and Packet Filter? ... differents données des logiciels fonctionnant auparavant sur wwin 95? ...
    (comp.security.firewalls)
  • Re: iptables and samba
    ... On 20 Oct 2002 19:49:34 GMT, Matthias Szusdziara ... >> $IPTABLES -P INPUT DROP ... >The trick is to enable the braodcasts and outgoing packets to pass behind ... >the packet filter. ...
    (comp.os.linux.security)