RE: [suse-security] stateful and dynamic inspection
does ipchains support stateful inspection and dynamic filtering in kernel 2.2.18?
No, the 2.2.x kernel packet filtering code (configured by ipchains) is not stateful. Note that the term "stateful inspection" belongs to the company Check Point, makers of the Firewall-1 line of products, so nothing besides Check Point's software supports "stateful inspection", strictly speaking.
whats about kernel 2.4.x and iptables?
Yes, the 2.4.x kernel PF code (netfilter, which is configured with the iptables tool) is stateful.
I found nothing on the web which describes the different filter functions on different network layers.
Hmm, have you read the Netfilter documentation? And do you know what stateful filtering is? If you've got in-depth questions, there's the netfilter mailing list and the ultimate reference: the source code itself.
Could anyone give me a short description which functions are implemented in kernels 2.2.1x and 2.4.x, or give me a link about these topics?
Well, the reference site is http://netfilter.kernelnotes.org, but I can't establish a connection at the moment. Just input "netfilter linux 2.4 iptables" to your favourite search engine and you should get enough hits to keep yourself busy for a while. HTH Tobias
participants (1)
-
Reckhard, Tobias