On Jun 29, 2004, at 9:51 AM, <larry@...> wrote:
> Is there any plans of native pre/post install scripts for iptables
> in fwb-2.0, as long as I can use custom install script its ok but...
yes, it is on the list but won't make it to 2.0
> ...
> Is there other solution for distributed firewall management,
> exept lufs (http://lufs.sf.net) that I use, but it's not portable
> (imagine win2k management station)??
>
not sure what you mean. 2.0 works on windows 2000 and XP (as well as
Macintosh) and uses ssh to talk to the firewall. It can be used for
remote firewall management already.
> GUI REQ: undo buton or/and versioning in xxx.fw files e.g fw$VERSION.fw
undo is hard to implement but is on the list.
Versioning is currently possible with 2.0 because it has built-in RCS.
You can document your changes in RCS, you can always roll back or
create a branch.
> uploded to firewall allowing easy return to last known good config.
> Policy guard "don't cut these stations from management", even
> that this have to be incorporated into compilers, or better
> default object "management station" ??
>
hmm, may be. Please file a feature request so it won't fall through
cracks.
> P.S As far as the policy and the library files are xml,
> is there any ongoing effort for web based GUI?
>
no, and there won't be. Running web server on the firewall creates too
many problems.
--vk
|