IPfilter
[Top] [All Lists]

Re: IPFilter 5.0.0 - feedback?

To: Casper.Dik@Sun.COM
Subject: Re: IPFilter 5.0.0 - feedback?
From: Jaroslaw Rafa <raj@ap.krakow.pl>
Date: Sat, 13 Jan 2007 18:55:20 +0100 (MET)
Cc: ipfilter@coombs.anu.edu.au
Delivered-to: sp-com-lists@consult.net
Delivered-to: ipfilter-list@securepoint.com
In-reply-to: <200701131742.l0DHgEfG019115@vaticaan.holland.sun.com> from "Casper.Dik@Sun.COM" at "Jan 13, 7 06:42:14 pm"
Sender: owner-ipfilter@coombs.anu.edu.au
Casper.Dik@Sun.COM napisal(a):
> 
> That's a very "big" question as it covers many OSes.
> 
> In Solaris, outgoing packets do carry quite a bit of information
> (process credential and often the process ID)
[...]
> It seems that in many OSes, such decisions would need to be made
> at a higher level, e.g., in the connect() or sendto() system calls.

Actually, I need it on Solaris 9. Can you point me to some ideas?
And I'm still curious if it's possible to use "auth" and/or "preauth" rules
in ipfilter in some way to achieve this? They are undocumented, and I don't
know what can they be used for...
Regards,
   Jaroslaw Rafa
   raj@ap.krakow.pl
-- 
Spam, wirusy, spyware... masz dość? Jest alternatywa!
http://www.firefox.pl/   ---   http://www.thunderbird.pl/
Szybciej. Łatwiej. Bezpieczniej. Internet tak jak lubisz.


<Prev in Thread] Current Thread [Next in Thread>