Search the web
Sign In
New User? Sign Up
SnapGearGroup · SnapGear
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Message search is now enhanced, find messages faster. Take it for a spin.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Feature Request   Message List  
Reply | Forward Message #962 of 1136 |
After noticing that the default Packet Filtering rules have changed between
3.1.5 and 4.0.2, I'm wondering if anyone else would be interested in seeing the
default rules "surfaced" to the main packet filtering display.

I'm not talking about the default rules about RFC1918 and such that you can edit
or disable, but rather the rules that control the default relationship between
interfaces labeled as "LAN", "DMZ", or "Internet".

I would find it enormously useful to have these rules listed along with the
rules that I write. It would be much easier to be certain that I have a clean
and effective list of rules if I could see them all in one human-readable
location.

I know that I can read the raw iptables under "Custom Firewall Rules", but I
find reading raw chains (especially written by someone else) more than a little
aggravating.

I'd be happy even if I couldn't change the default rules (or even change their
order), but it sure would be nice to see them.

Josh




Fri Jul 3, 2009 1:52 pm

jgee78...
Offline Offline
Send Email Send Email

Forward
Message #962 of 1136 |
Expand Messages Author Sort by Date

After noticing that the default Packet Filtering rules have changed between 3.1.5 and 4.0.2, I'm wondering if anyone else would be interested in seeing the...
jgee78@...
jgee78...
Offline Send Email
Jul 3, 2009
1:53 pm

Yes, making all rules visible and possibly editable is planned. Ideally you could create your own firewall class (lan/internet/vpn/guest) in fact. It'd be good...
Tom Essebier
tom_essebier
Offline Send Email
Jul 7, 2009
5:35 am

Thanks Tom, That sounds really promising. Personally, I would put rule groups (which sound really helpful) and seeing/editing the default rules quite a bit...
jgee78@...
jgee78...
Offline Send Email
Jul 8, 2009
3:25 pm

You can acheieve the same effect by simply putting a 'deny all' rule at the bottom of the firewall rules list. That effectively overrides any default rules...
Martin Robinson
robinsmh
Offline Send Email
Jul 7, 2009
10:57 am
Advanced

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help