TCLUG Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [TCLUG:13767] IPCHAINS again...



  Hi,

On Mon, 21 Feb 2000, Peter Lukas wrote:

> Unlike CheckPoint, IPCHAINS isn't stateful, so you'll need to enable
> inbound replies (the easiest is to do the -y flag in your inbound rule).

Yup, figured it out now.

> Fortunately, the upcoming IPTABLES is stateful and has flags for
> "established" and "related."  I've been playing around with it for a while
> and it can simplify the rulebase a great deal.

I _do_ feel like a bit of an idiot for figuring out IPCHAINS instead of
just figuring out netfilters. Yes, I know netfilters is compatible, but
I haven't been able to get it to work perfectly yet, and I should've just
focused on that! Oh well.


-Yaron

--