On 23/02/13 19:27, Tom Eastep wrote: > Using ipsets is the only way that I would try such a thing. > > -Tom > > On 2/23/13 10:57 AM, "Cory Oldford" <[email protected] > <mailto:[email protected]>> wrote: > > The overhead associated with matching against the complete bogon > list is too much in my humble opinion. > > > Cory Oldford > > ------------------------------------------------------------------------ > *From: *"Dr. Jeffry A. Spain" <[email protected] > <mailto:[email protected]>> > *To: *"Shorewall Users" <[email protected] > <mailto:[email protected]>> > *Sent: *Saturday, February 23, 2013 12:38:14 PM > *Subject: *[Shorewall-users] Full Bogon Filtering > > What experience have users had using ShoreWall as a bogon filter > using the Team Cymru full bogon lists > (http://www.team-cymru.org/Services/Bogons/http.html)? The IPv4 > full bogon list contains over 4,600 separate networks that need to > be denied, and the IPv6 list over 68,300. Having not tried this > myself, I would be concerned a priori about ShoreWall server meltdown. > > Jeffry A. Spain, Network Administrator > Cincinnati Country Day School > > > > ------------------------------------------------------------------------------ > Everyone hates slow websites. So do we. > Make your web apps faster with AppDynamics > Download AppDynamics Lite for free today: > http://p.sf.net/sfu/appdyn_d2d_feb > _______________________________________________ > Shorewall-users mailing list > [email protected] > <mailto:[email protected]> > https://lists.sourceforge.net/lists/listinfo/shorewall-users > > > ------------------------------------------------------------------------------ > Everyone hates slow websites. So do we. Make your web apps faster > with AppDynamics Download AppDynamics Lite for free today: > > http://p.sf.net/sfu/appdyn_d2d_feb_______________________________________________ > Shorewall-users mailing list [email protected] > <mailto:[email protected]> > https://lists.sourceforge.net/lists/listinfo/shorewall-users > > > > -Tom > You do not need a parachute to skydive. You only need a parachute to > skydive twice. > > > > ------------------------------------------------------------------------------ > Everyone hates slow websites. So do we. > Make your web apps faster with AppDynamics > Download AppDynamics Lite for free today: > http://p.sf.net/sfu/appdyn_d2d_feb > > > _______________________________________________ > Shorewall-users mailing list > [email protected] > https://lists.sourceforge.net/lists/listinfo/shorewall-users I have tried this myself and I have to second what Tom said above, unfortunately I havn't rewritten the shell scripts for it yet after losing them in a hard disk crash had other things needed resolving first however the actual update of the ipsets will cause a bit of a spike especially if your firewall system is a low end machine (An intel i7 hexacore was taking a minute or two to chew through it it) but I created a shell script to download the lists whenever they were modified, compare them and then update the ipsets with changes only. I have been intending to implement this again myself and it would probably take as long to write a detailed explanation as it would to just go ahead and create the scripts again with comments.
I should have some free time this morning so I will try to get that done today and get back to you with the shell script and comments.
signature.asc
Description: OpenPGP digital signature
------------------------------------------------------------------------------ Everyone hates slow websites. So do we. Make your web apps faster with AppDynamics Download AppDynamics Lite for free today: http://p.sf.net/sfu/appdyn_d2d_feb
_______________________________________________ Shorewall-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/shorewall-users
