Re: [SOLVED] Re: Native support of counting rules?

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On 03.01.2013 18:27, netfilter-owner@xxxxxxxxxxxxxxx wrote:
On 03/01/13 17:05, Jan Engelhardt wrote:
On Thursday 2013-01-03 15:56, Jan Vales wrote:

Hi,

why dont you use ...
iptables-save | grep "\-A" | wc -l

grep ^-A

But the foremost question is: how is the rule count alone going to be
useful?


I dont think its useful at all - I just like stats and wanted to help ;)

Especially with OP's requirement to allow non-root users to view this count.
Therefore know that/when you changed something.

you can swap the whole ruleset, as long as the total count of rules stays the same, this test won't detect it, therefore is totally unreliable. Nothing but stats, yes.

--
To unsubscribe from this list: send the line "unsubscribe netfilter" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html


[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux