Great Circle Associates Network-Automation
(June 2005)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: ACL compiler [was: Network Automation: An Architects View]
From: "Michael T. Halligan" <mhalligan @ bitpusher . com>
Date: Sat, 25 Jun 2005 18:08:05 -0700
To: tedkaz @ optonline . net
Cc: DJ Gregor <dj @ gregor . com>, network-automation @ greatcircle . com
In-reply-to: <1119747621.14548.2.camel@inyoureyes.linsolutions.com>
References: <5.1.0.14.0.20050521155048.025ab230@mail.eclipse.co.uk> <17039.36357.794569.744848@perdition.linnaean.org> <c0fc3ae805052217037a1c0971@mail.gmail.com> <20050524115708.E40415@skink.reptiles.org> <66b6f3369bde6fa64632f383d2bc4500@gregor.com> <1119747621.14548.2.camel@inyoureyes.linsolutions.com>
Reply-to: mhalligan @ bitpusher . com
User-agent: Mozilla Thunderbird 1.0.2 (Macintosh/20050317)

Ted,

I believe you can create a redhat-style iptables file, after you've 
created your policy by running iptables-save .. Not the best
solution, but a workable one.

Otherwise, FWbuilder is nice, but in my experience it's somewhat buggy. 
I've never been able to get it to work reliably enough
to create a policy all the way through on any platform it supports.

Michael

Ted Kaczmarek wrote:

>On Tue, 2005-05-24 at 12:25 -0400, DJ Gregor wrote:
>  
>
>>In terms of ACL compilers, has anyone looked at Firewall Builder?  It  
>>looks to have a general XML format that defines the policy (although at  
>>a low-level, in terms of ports and devices), along with translators  
>>from the XML format into implementation-specific configuration  
>>statements.
>>
>>	http://www.fwbuilder.org/
>>
>>I've also seen the same thing done in a commercial product where not  
>>only the firewall configuration, but the entire device configuration  
>>was specified in an XML language that was translated to operating  
>>system-specific configurations (for multiple OSes, even).  The XML  
>>configurations were per-device, not per-network, however.
>>
>>	
>>	- djg
>>
>>    
>>
>I would like it a lot more if it generated redhat style iptables
>file :-)
>It is a most popular tool used by lots of people I know.
>
>Ted
>
>
>  
>


-- 
-------------------
BitPusher, LLC
http://www.bitpusher.com/
1.888.9PUSHER
(415) 724.7998 - Mobile




Follow-Ups:
References:
Indexed By Date Previous: Re: ACL compiler [was: Network Automation: An Architects View]
From: Ted Kaczmarek <tedkaz@optonline.net>
Next: Re: ACL compiler [was: Network Automation: An Architects View]
From: Vadim Kurland <vadim@vk.crocodile.org>
Indexed By Thread Previous: Re: ACL compiler [was: Network Automation: An Architects View]
From: Ted Kaczmarek <tedkaz@optonline.net>
Next: Re: ACL compiler [was: Network Automation: An Architects View]
From: Vadim Kurland <vadim@vk.crocodile.org>

Google
 
Search Internet Search www.greatcircle.com