On 23/02/13 19:27, Tom Eastep wrote:
> Using ipsets is the only way that I would try such a thing.
>
> -Tom
>
> On 2/23/13 10:57 AM, "Cory Oldford" <[email protected]
> <mailto:[email protected]>> wrote:
>
>     The overhead associated with matching against the complete bogon
>     list is too much in my humble opinion.
>
>
>     Cory Oldford
>
>     ------------------------------------------------------------------------
>     *From: *"Dr. Jeffry A. Spain" <[email protected]
>     <mailto:[email protected]>>
>     *To: *"Shorewall Users" <[email protected]
>     <mailto:[email protected]>>
>     *Sent: *Saturday, February 23, 2013 12:38:14 PM
>     *Subject: *[Shorewall-users] Full Bogon Filtering
>
>     What experience have users had using ShoreWall as a bogon filter
>     using the Team Cymru full bogon lists
>     (http://www.team-cymru.org/Services/Bogons/http.html)? The IPv4
>     full bogon list contains over 4,600 separate networks that need to
>     be denied, and the IPv6 list over 68,300. Having not tried this
>     myself, I would be concerned a priori about ShoreWall server meltdown.
>
>     Jeffry A. Spain, Network Administrator
>     Cincinnati Country Day School
>
>
>     
> ------------------------------------------------------------------------------
>     Everyone hates slow websites. So do we.
>     Make your web apps faster with AppDynamics
>     Download AppDynamics Lite for free today:
>     http://p.sf.net/sfu/appdyn_d2d_feb
>     _______________________________________________
>     Shorewall-users mailing list
>     [email protected]
>     <mailto:[email protected]>
>     https://lists.sourceforge.net/lists/listinfo/shorewall-users
>
>     
> ------------------------------------------------------------------------------
>     Everyone hates slow websites. So do we. Make your web apps faster
>     with AppDynamics Download AppDynamics Lite for free today:
>     
> http://p.sf.net/sfu/appdyn_d2d_feb_______________________________________________
>     Shorewall-users mailing list [email protected]
>     <mailto:[email protected]>
>     https://lists.sourceforge.net/lists/listinfo/shorewall-users 
>
>
>
> -Tom
> You do not need a parachute to skydive. You only need a parachute to
> skydive twice.
>
>
>
> ------------------------------------------------------------------------------
> Everyone hates slow websites. So do we.
> Make your web apps faster with AppDynamics
> Download AppDynamics Lite for free today:
> http://p.sf.net/sfu/appdyn_d2d_feb
>
>
> _______________________________________________
> Shorewall-users mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/shorewall-users
I have tried this myself and I have to second what Tom said above,
unfortunately I havn't rewritten the shell scripts for it yet after
losing them in a hard disk crash had other things needed resolving first
however the actual update of the ipsets will cause a bit of a spike
especially if your firewall system is a low end machine (An intel i7
hexacore was taking a minute or two to chew through it it) but I created
a shell script to download the lists whenever they were modified,
compare them and then update the ipsets with changes only.  I have been
intending to implement this again myself and it would probably take as
long to write a detailed explanation as it would to just go ahead and
create the scripts again with comments.

I should have some free time this morning so I will try to get that done
today and get back to you with the shell script and comments.

Attachment: signature.asc
Description: OpenPGP digital signature

------------------------------------------------------------------------------
Everyone hates slow websites. So do we.
Make your web apps faster with AppDynamics
Download AppDynamics Lite for free today:
http://p.sf.net/sfu/appdyn_d2d_feb
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to