What's the plan for future "firewalling" support ?
the future directions page lists "Minor or internal improvements" "Stronger firewalling rules (deny stuffed packets, etc.)"
In the mean time, has anybody had a look at the rc.firewall script at
http://www.jsmoriss.dyndns.org/linux/firewall.htmlIt seems quite extensive and has been working great for me.
excerpt from site.
"rc.firewall is an ipchains-based firewall script with extensive support for network services (IPSec, VTUN, NFS, SMB, Napster, Proxies, etc.), masquerading, port forwarding (including definitions for network games), and IP accounting. All services are self-contained modules which can be prioritized and installed easily. Protections include spoofing, stuffed routing / masqerading, DoS, smurf attacks, outgoing port scans, and much more. rc.firewall also supports multiple private and public interfaces with unique rules for each interface/service. This allows the creation of a De-Militarized Zone (DMZ). rc.firewall is distributed under the General Public License (GPL) terms."