Mailinglist Archive: opensuse-features (107 mails)

< Previous Next >
[openFATE 308441] Use ip_set kernel option
  • From: fate_noreply@xxxxxxx
  • Date: Sat, 5 Dec 2009 13:24:11 +0100 (CET)
  • Message-id: <feature-308441-2@xxxxxxxxxxxxxx>
Feature changed by: Jan Engelhardt (jengelh)
Feature #308441, revision 2
Title: Use ip_set kernel option

Package Wishlist: Unconfirmed
Priority
Requester: Desirable

Requested by: Don Hughes (dehughes)

Description:
Compile RT kernel with the ip_set netfilter option, and include the
ipset module in the distribution.
The ipset module ( http://ipset.netfilter.org ) can be very useful in
building firewalls for large networks.  It needs the ip_set kernel
module.
Creating a firewall black list with just iptables could entail a filter
table with a very large number of entries which can have a significant
performance impact. ipset can be used to build much more eficient
lookup tables, improving performance.

+ Discussion:
+ #1: Jan Engelhardt (jengelh) (2009-12-05 13:23:58)
+ Reword this request: include "xtables-addons" (contains ipset already,
+ and no kernel recompile is needed). SRPM is in
+ http://jftp.medozas.de/.



--
openSUSE Feature:
https://features.opensuse.org/308441

< Previous Next >
List Navigation
This Thread
  • No further messages
References