[ale] Centrailized iptables rules management

Chris Ricker kaboom at oobleck.net
Fri Jan 19 13:13:46 EST 2007


On Fri, 19 Jan 2007, Jim Popovitch wrote:

> On Fri, 2007-01-19 at 11:54 -0500, Jerry Yu wrote:
> > I use CVS (sometimes RCS) to check in such rules. Filing them per host
> > or per type is more or less of personal preference.
> > Both a shell script to generate the rules and the saved working rules
> > are candidates to check in. 
> 
> Oooohh, good idea. Thanks.

If you want to go all out, it wouldn't be hard to extend rancid 
<http://www.shrubbery.net/rancid/> to support iptables

later,
chris



More information about the Ale mailing list