TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Iptables Tutorial 1.2.2

69 点作者 federicoponzi超过 7 年前

10 条评论

samueloph超过 7 年前
www.frozentux.net uses an invalid security certificate. The certificate expired on October 19, 2017, 9:59 PM. The current time is October 20, 2017, 11:04 AM.<p>Here&#x27;s an alternate url<p><a href="https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20170921014253&#x2F;https:&#x2F;&#x2F;www.frozentux.net&#x2F;iptables-tutorial&#x2F;iptables-tutorial.html" rel="nofollow">https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20170921014253&#x2F;https:&#x2F;&#x2F;www.froze...</a>
krylon超过 7 年前
I hate to say it, but I will never forget the day I first stumbled upon PF.<p>Up to that point, setting up a router&#x2F;firewall had been exceedingly painful, using Linux and iptables.<p>The syntax of pf.conf is beautiful. Somebody (I forgot who) once said that in order to write a rule set one needs to consult the (excellent) man page constantly, but once it is done, reading and <i>understanding</i> it takes no effort at all. As far as the &quot;UI&quot; goes, PF is so far ahead of anything I know of that most other metrics to judge a firewall &#x2F; packet filter by seem to disappear.<p>Just to be clear: I have nothing against Linux, in fact most of my computers run Linux. But the syntax of pf.conf is just so sweet, once I tasted it, it spoiled me forever. And now iptables scripts look like something out of a Lovecraftian nightmare.
gtirloni超过 7 年前
nftables is iptables&#x27; successor:<p><a href="http:&#x2F;&#x2F;www.netfilter.org&#x2F;projects&#x2F;nftables" rel="nofollow">http:&#x2F;&#x2F;www.netfilter.org&#x2F;projects&#x2F;nftables</a><p><a href="https:&#x2F;&#x2F;hn.algolia.com&#x2F;?query=nftables" rel="nofollow">https:&#x2F;&#x2F;hn.algolia.com&#x2F;?query=nftables</a>
评论 #15515679 未加载
评论 #15515982 未加载
评论 #15515765 未加载
ausjke超过 7 年前
This tutorial is pretty old actually. Hope someone updates it, then we have nftables on the way to replace iptables, so might be just update to nftables directly.<p>I found &#x27;nft&#x27;, along with other commands such as &#x27;ip&#x27; and &#x27;tc&#x27; are pretty hard to use. I hope someone can create all possible auto-completion to guide the users, it is so hard to memorize those abbrev tags&#x2F;options for those commands.
评论 #15516352 未加载
trappist超过 7 年前
Copyright 2006, &quot;...the new Linux 2.4.x kernels&quot;, dead SSL cert
iakie超过 7 年前
For those referring nftables, there’s a LOT of stuff in iptables that doesn&#x27;t work in nftables: from simple things like xt_time to complex ones like xt_TPROXY. so nftables isn&#x27;t a viable replacement for iptables just yet. In theory there&#x27;s a compat layer in nftables to get around those, but I have never able to successfully build a binary that works.
arca_vorago超过 7 年前
I&#x27;m currently working on an nftables setup script (removes iptables). I plan to release under gplv3. As I understand it nftables is designed to replace iptables (though they both use netfilter methinks), so I am ripping out iptables everywhere currently.<p>That said, I love the effort in this documentation.
nwmcsween超过 7 年前
Eventually someone or me should make a firewall &#x27;fs&#x27; with fuse, it would map nicely and would be much less of a pain in the ass to work with.
tra3超过 7 年前
Does anyone know of a humane QoS tutorial? I&#x27;ve tried to understand it a few times but it&#x27;s been beyond me.
spapas82超过 7 年前
Please keep in mind that RHEL &#x2F; Centos 7 has changed the default firewall from iptables to firewalld.
评论 #15515930 未加载