NetFilter
[Top] [All Lists]

Re: Dynamic chain alternatives

To: "Gary W. Smith" <gary@primeexalia.com>
Subject: Re: Dynamic chain alternatives
From: Sven Schuster <schuster.sven@gmx.de>
Date: Mon, 20 Nov 2006 07:55:09 +0100
Cc: netfilter@lists.netfilter.org
Delivered-to: sp-com-lists@consult.net
Delivered-to: netfilter-list1@securepoint.com
In-reply-to: <57F9959B46E0FA4D8BA88AEDFBE5829024ED10@pxtbenexd01.pxt.primeexalia.com>
List-archive: </pipermail/netfilter>
List-help: <mailto:netfilter-request@lists.netfilter.org?subject=help>
List-id: General discussion and user questions <netfilter.lists.netfilter.org>
List-post: <mailto:netfilter@lists.netfilter.org>
List-subscribe: <https://lists.netfilter.org/mailman/listinfo/netfilter>, <mailto:netfilter-request@lists.netfilter.org?subject=subscribe>
List-unsubscribe: <https://lists.netfilter.org/mailman/listinfo/netfilter>, <mailto:netfilter-request@lists.netfilter.org?subject=unsubscribe>
References: <57F9959B46E0FA4D8BA88AEDFBE5829024ED10@pxtbenexd01.pxt.primeexalia.com>
Sender: netfilter-bounces@lists.netfilter.org
User-agent: Mutt/1.5.12-2006-07-14
Hi Gary,

On Sun, Nov 19, 2006 at 05:23:53PM -0800, Gary W. Smith told us:
> I have a need to create a dynamic table in that will have random IP's
> inserted and deleted on a regular basis.  Currently we do this by
> creating a chain at load time and on a scheduled basis we flush that
> chain and then to a iptables-restore -n < dynamic_rules.txt.  
>
> Is there a better approach to doing this?

what about using ipset??
http://www.netfilter.org/projects/ipset/index.html

hope that helps,


Sven

> Gary Wayne Smith
>

-- 
Linux zion.homelinux.com 2.6.18-1.2849.fc6xen #1 SMP Fri Nov 10 13:56:52 EST 
2006 i686 athlon i386 GNU/Linux
 07:54:34 up 4 days,  9:12,  1 user,  load average: 0.07, 0.13, 0.13

Attachment: pgpBhPmPe5vCt.pgp
Description: PGP signature

<Prev in Thread] Current Thread [Next in Thread>