LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > SUSE / openSUSE
User Name
Password
SUSE / openSUSE This Forum is for the discussion of Suse Linux.

Notices


Reply
  Search this Thread
Old 06-18-2006, 12:53 AM   #1
huxflux
Member
 
Registered: Mar 2005
Posts: 33

Rep: Reputation: 15
Where is the iptables config file?


In Fedora or MDK that file is in /etc/sysconfig/iptables . but where is it in suse?

thx
 
Old 06-18-2006, 01:44 AM   #2
jschiwal
LQ Guru
 
Registered: Aug 2001
Location: Fargo, ND
Distribution: SuSE AMD64
Posts: 15,733

Rep: Reputation: 682Reputation: 682Reputation: 682Reputation: 682Reputation: 682Reputation: 682
You will probably want to read:

/usr/share/doc/packages/SuSEfirewall2/README and /etc/sysconfig/SuSEfirewall2

before studying /sbin/SuSEfirewall2
 
Old 06-18-2006, 09:17 AM   #3
huxflux
Member
 
Registered: Mar 2005
Posts: 33

Original Poster
Rep: Reputation: 15
yeah.. thanks for nothing.
 
Old 06-18-2006, 11:06 AM   #4
UK MAdMaN
Member
 
Registered: Jul 2004
Location: Manchester, England
Distribution: Gentoo
Posts: 211

Rep: Reputation: 30
Well, you're gonna get a lot of help with that attitude.
 
Old 06-20-2006, 05:24 AM   #5
jschiwal
LQ Guru
 
Registered: Aug 2001
Location: Fargo, ND
Distribution: SuSE AMD64
Posts: 15,733

Rep: Reputation: 682Reputation: 682Reputation: 682Reputation: 682Reputation: 682Reputation: 682
A statefull firewall is setup dynamically using the scripts I mentioned, and not from a static table.

From the FAQ file in /usr/share/doc/packages/SuSEfirewall2/:
Quote:
13. Why is SuSEfirewall2 so slow? / Can't you just use iptables-restore?

SuSEfirewall2 is implemented in bourne shell which is not exactly the fastest
thing on earth especially if it has that much work to do as SuSEfirewall2.
Administrators still prefer bourne shell scripts because of readability *cough*
. To be able to use iptables-restore SuSEfirewall2 would need a lot more logic
than what is be possible with bourne shell as it would need to sort and reorder
the rules for example. Furthermore interfaces are not static. They can
arbitrarily appear and disapper with different names so a generic solution
can't just dump the rules with iptables-store and re-apply them with
iptables-restore.
The file you are looking for simply doesn't exist.

Also consider this quote from "Iptables Tutorial 1.2.0" by Oskar Andreason:
Quote:
...can iptables-restore handle any kind of scripting? So far, no, it cannot and it will most probably never be able to. This is the main flaw in using iptables-restore since you will not be able to do a huge set of things with these files. ...
This is from the /sbin/SuSEfirewall2 script itself:
Code:
###########################################################################
#                                                                         #
# The configuration file for this firewall script is                      #
# /etc/sysconfig/SuSEfirewall2                                            #
#                                                                         #
# Please make only modifications to this script if you know what you      #
# are doing! A small explanation of the setup can be found in             #
# /usr/share/doc/packages/SuSEfirewall2/README                            #
#                                                                         #
# For new-user help concerning configuring this firewall, take a look at  #
# the configuration file /etc/sysconfig/SuSEfirewall2 - it tells          #
# you all                                                                 #
# (if not: sorry, but configuring a packet filter/screening router is NOT #
# trivial - you must know what you are doing and what it actually does!)  #
#                                                                         #
###########################################################################

Last edited by jschiwal; 06-20-2006 at 05:27 AM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Location iptables config file freakin'me Linux - Software 10 08-14-2005 08:01 AM
Where is the iptables default config file stored under SuSe 9.1 skunkburner SUSE / openSUSE 4 02-03-2005 10:10 AM
where is the iptables dufault rules config file? ayiiq180 Linux - Software 2 12-18-2004 02:42 AM
Lan Config file / internet config file Raven_X_Neo Linux - Networking 1 10-30-2002 01:05 PM
location of iptables config file munisp Linux - Networking 1 12-13-2001 06:37 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > SUSE / openSUSE

All times are GMT -5. The time now is 03:48 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration