Security Basics mailing list archives
Re: Syncing iptables [state, was rules] between two servers
From: Keith Morgan <keith.morgan () terradon com>
Date: Thu, 20 Apr 2006 11:52:50 -0400
I've often wondered about not only synching firewall rules, but synching the state table in /proc/net/ip_conntrack. This would be a major hurdle crossed for firewall clustering. Synching the rules themselves is pretty trivial from a scripting point of view. Synching the state table on the other hand.... On Thu, 2006-04-13 at 05:36 -0500, Stephen Barron wrote:
Thomas Howard Uphill wrote:Lars Solberg wrote:Hi Is there anyone that know about how I can "sync" iptables rules on two different servers? The plan is to have (on one of the servers) a script that automaticly block ip adresses with iptables depending on different conditions. When that ip adress is blocked I want it to automaticly be blocked on another server to.
<snip> ********************************************************************************************** IMPORTANT: The contents of this email and any attachments are confidential. They are intended for the named recipient(s) only. If you have received this email in error, please notify the system manager or the sender immediately and do not disclose the contents to anyone or make copies thereof. *** eSafe scanned this email for viruses, vandals, and malicious content. *** ********************************************************************************************** ------------------------------------------------------------------------- This List Sponsored by: Webroot Don't leave your confidential company and customer records un-protected. Try Webroot's Spy Sweeper Enterprise(TM) for 30 days for FREE with no obligation. See why so many companies trust Spy Sweeper Enterprise to eradicate spyware from their networks. FREE 30-Day Trial of Spy Sweeper Enterprise http://www.webroot.com/forms/enterprise_lead.php --------------------------------------------------------------------------
Current thread:
- Syncing iptables rules between two servers Lars Solberg (Apr 11)
- Re: Syncing iptables rules between two servers Gaz Wilson (Apr 11)
- Re: Syncing iptables rules between two servers ilaiy (Apr 11)
- Re: Syncing iptables rules between two servers Thomas Howard Uphill (Apr 11)
- Re: Syncing iptables rules between two servers Stephen Barron (Apr 13)
- Re: Syncing iptables [state, was rules] between two servers Keith Morgan (Apr 20)
- Re: Syncing iptables rules between two servers Stephen Barron (Apr 13)
- Re: Syncing iptables rules between two servers Ayaz Ahmed Khan (Apr 11)
- Re: Syncing iptables rules between two servers Christopher Jastram (Apr 11)
- Re: Syncing iptables rules between two servers Jason Nicholls (Apr 11)
- Re: Syncing iptables rules between two servers Stoimen Gerenski (Apr 11)
- Re: Syncing iptables rules between two servers Ansgar -59cobalt- Wiechers (Apr 11)
- Re: Syncing iptables rules between two servers Drew Leske (Apr 11)
- Re: Syncing iptables rules between two servers Bosse Klykken (Apr 11)
- RE: Syncing iptables rules between two servers Burton Strauss (Apr 11)
- Re: Syncing iptables rules between two servers Dirk Dierickx (Apr 13)
- <Possible follow-ups>
- Re: Syncing iptables rules between two servers Bob Toxen (Apr 11)
(Thread continues...)