[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Firewalling IPv6 - an easy way?



Hi Andrew,

Andrew Ruthven wrote:
Hi Chris

On Sun, 2007-08-12 at 17:07 +0100, Chris Boot wrote:
I've been running IPv6 locally without much trouble at all. Now I'd like to build a firewall on my router and had a good look around for debian packages for IPv6 compatible firewall software and I came up blank. I currently use Shorewall for IPv4 and it works really nicely but there clearly isn't any support in that for IPv6. I see there's a 6wall that's based on Shorewall in LEAF/Bering, but it's really old and not packaged. I'd rather not have to build my own rules using ip6tables if possible.

I'm sorry, but the bad news is that currently you'll have to write the
ip6table rules by hand.  The good news is that you might be able to use
the IPv4 rules as a base and just do some heavy editting.

Thanks. Never mind, I guess it is the manual method then. Is there a Debian-recommended way of applying manual ip6tables rules? I was thinking of running an ip6tables-restore in post-up in /etc/network/interfaces, would that be a sensible option?

Does anyone have any best-practice sample IPv6 firewall rules for a server (i.e. not router/workstation)?

Many thanks,
Chris



Reply to: