{"id":8,"date":"2005-01-05T17:08:00","date_gmt":"2005-01-06T01:08:00","guid":{"rendered":"http:\/\/outflux.net\/blog\/archives\/2005\/01\/05\/suse-firewall\/"},"modified":"2005-01-06T03:23:36","modified_gmt":"2005-01-06T11:23:36","slug":"suse-firewall","status":"publish","type":"post","link":"https:\/\/outflux.net\/blog\/archives\/2005\/01\/05\/suse-firewall\/","title":{"rendered":"SuSE Firewall"},"content":{"rendered":"<p>Started looking at the SuSE firewall scripts today.  They&#8217;re quite nice, actually.  So far, they look like they&#8217;ll support everything I want to do without any trouble.  What&#8217;s really nice about it is the resulting script is much more readable than a string of <code>iptables<\/code> commands (where I&#8217;d have to specify the ACCEPT, NAT, and FORWARD for inbound services generally in different places).<\/p>\n<p>What I&#8217;d really like to see would be an <code>m4<\/code>-based version of the script.  It&#8217;s good enough for <code>sendmail<\/code> and <code>autoconf<\/code>, why not <code>iptables<\/code>?  :)  That would totally rock, because then I&#8217;d be able to see the resulting list of <code>iptables<\/code> commands.  I bet there&#8217;s a place somewhere to see them now; but I just haven&#8217;t looked.<\/p>\n<p>I&#8217;m hoping that this firewall configuration will play nice with <code>heartbeat<\/code>, which I&#8217;ll be using to do some high-availability work on the firewall pair.  I&#8217;ve had to fight a little with SuSE over the interface names (I want to name the network interfaces after their function, not their boot order).  <code>udev<\/code> has been quite friendly, but SuSE seems to have special meanings for various separator characters.  I wanted to have &#8220;eth-internal&#8221;, etc, but it seems to strip &#8220;eth-&#8220;.  And &#8220;eth_internal&#8221; turns into &#8220;eth\/internal&#8221;.  So, I&#8217;m just using &#8220;etinternal&#8221; instead.  :P<\/p>\n<p style='text-align:left'>&copy; 2005, <a href=\"https:\/\/outflux.net\/blog\/\">Kees Cook<\/a>. This work is licensed under a <a rel=\"license\" href=\"http:\/\/creativecommons.org\/licenses\/by-sa\/4.0\/\">Creative Commons Attribution-ShareAlike 4.0 License<\/a>.<br \/><a rel=\"license\" href=\"http:\/\/creativecommons.org\/licenses\/by-sa\/4.0\/\"><img decoding=\"async\" alt=\"CC BY-SA 4.0\" style=\"border-width:0\" src=\"https:\/\/i.creativecommons.org\/l\/by-sa\/4.0\/88x31.png\" \/><\/a> <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Started looking at the SuSE firewall scripts today. They&#8217;re quite nice, actually. So far, they look like they&#8217;ll support everything I want to do without any trouble. What&#8217;s really nice about it is the resulting script is much more readable than a string of iptables commands (where I&#8217;d have to specify the ACCEPT, NAT, and [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7,6],"tags":[],"_links":{"self":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts\/8"}],"collection":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/comments?post=8"}],"version-history":[{"count":0,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts\/8\/revisions"}],"wp:attachment":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/media?parent=8"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/categories?post=8"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/tags?post=8"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}