Re: Best version of IPFilters for Solaris

This is a discussion on Re: Best version of IPFilters for Solaris within the IPFilter forums, part of the System Security and Security Related category; Mangesh wrote: > Dear Scott, > > I am using OpenBSD 3.0 with ipfilter 3.4.35 and is ...


Go Back   Usenet Forums > System Security and Security Related > IPFilter

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 12-08-2004
Attila Fülöp
 
Posts: n/a
Default Re: Best version of IPFilters for Solaris

Mangesh wrote:
> Dear Scott,
>
> I am using OpenBSD 3.0 with ipfilter 3.4.35 and is handling a good
> amount of traffic.
> I have increase IPSTATE_SIZE from 5737 to 500 009 and
> IPSTATE_MAX from 4013 to 350 003
> and currenly working fine for me.
>
> I have tried to with Open BSD 3.5 with ipfilter 4.1.3 works for low
> traffic but if traffic
> goes up then machine gets dump and have to restart the machine so i
> think you should not
> use this combination on production environment ( Anybody on the list
> using this combination ??????? )


I used 4.1.2, 4.1.3 and 4.1next with OpenBSD 3.5. I had to patch 4.1.2
to get it usable, but even with the recent 4.1next we have issues with
the ipfilter box stalling every now and then.

Did you use the ipf ftp-proxy nat module with 4.1.3? I had the feeling
that the stalls may be related to nate'ed ftp traffic. Not sure about
that though.

So I would urge you not to use 4.1.3 right now. Sorry, but I can't tell
you anything about 3.4.x on OpenBSD since my rule set makes heavy use of
macros (to make it editable by ppl not speaking ipfilter). As far as i
know, 3.4.x does not support macros, so i can't downgrade to it.


-- Attila

>
>
> Regards
> Mangesh
>
>
>
> Scott wrote:
>
>> I was wondering what the best (most stable) version of IPFilters would
>> be for a production Solaris 9 box. I had issues with 4.1.3 and can't
>> have my boxes drop on me..
>>
>> Thanks..
>> Scott
>>

>
>

Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 10:10 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0