Re: ipt_string and Kernel 2.6 !!URGENT!!

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



> I JUST WANT TO RUN THE IPT_STRING ON A KERNEL 2.6.

Jason is correct, IPT_STRING is a toy and should not be used for filtering
packets on a firewall in an enterprise setup.  What happens to your
IPT_STRING match when someone sends TCP packets one byte at a time?

A transparent proxy with a userspace application level filter is likely a
better choice.

-- 
If you have received this email in error, you are required to shred it
immediately, add some nutmeg, three egg whites and a dessertspoonful of
caster sugar.  Whisk until soft peaks form, then place in a warm oven for 40
minutes.  Remove promptly and let stand for 2 hours before adding some
decorative kiwi fruit and cream.  Then notify me immediately by return email
and eat the original message.

Attachment: pgpUF5lJlrq6J.pgp
Description: PGP signature


[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux