pfilter provides an easy to use method under both ipchains or iptables based linux systems to generate packet filtering rulesets.
Be the first to post a text review of linux packet filtering. Rate and review a project by clicking thumbs up or thumbs down in the right column.
Added the endpoint network service definition. Added code so that pseudo interfaces created by alias directives will have the correct broadcast address (since the ifconfig command doesn't always do this correctly). Fixed the ping service ruleset so that error messages are not being generated when there is no broadcast address for an interface. Fixed the pfilter command so that it doesn't delay for dns timeouts. Updated the pfilter man page to show more of the missing command line options. Made pfilter more error tolerant: If no interfaces found when pfilter started, pfilter still starts. If no pfilter configuration file found, pfilter uses a default file. If pfilter cannot write out expanded source or commands files, still starts. Added syslog logging of pfilter start/stop/restart. Expanded the definition of the ping service to include icmp type 0. Made ping from anywhere be allowed. Added logic to determine the kernel name as well as version. Fixed the nfs service definition to work in more shells. Turned off martian packet logging if logging level is set to none. Allowed interface names to be letter(s) possibly followed by digit(s), instead of letter(s) always followed by digit(s).
Added the endpoint network service definition. Added code so that pseudo interfaces created by alias directives will have the correct broadcast address (since the ifconfig command doesn't always do this correctly). Fixed the ping service ruleset so that error messages are not being generated when there is no broadcast address for an interface. Fixed the pfilter command so that it doesn't delay for dns timeouts. Updated the pfilter man page to show more of the missing command line options. Made pfilter more error tolerant: If no interfaces found when pfilter started, pfilter still starts. If no pfilter configuration file found, pfilter uses a default file. If pfilter cannot write out expanded source or commands files, still starts. Added syslog logging of pfilter start/stop/restart. Expanded the definition of the ping service to include icmp type 0. Made ping from anywhere be allowed. Added logic to determine the kernel name as well as version. Fixed the nfs service definition to work in more shells. Turned off martian packet logging if logging level is set to none. Allowed interface names to be letter(s) possibly followed by digit(s), instead of letter(s) always followed by digit(s).
Be the first person to add a text review.
Copyright © 2010 Geeknet, Inc. All rights reserved. Terms of Use
Thanks for your rating!
Would you also like to write a review?
Thanks for your review!
Get credit for your review by logging in via OpenID. Click your account provider: