IPChains vs Cisco IOS Packer Filters


Can anyone tell me whether the Packet Filter on the Cisco IOS does statefull packet inspection ? and whether I'll be losing by replacing it with IPChains on Kernel 2.2.17?
Biggest reason being I know nothing about the Cisco IOS and it's also a leased router to which I don't have telnet or console access (only the ISP's net is allowed access to) and I keep on needing to alter rules and it's a bugger having to wait for the ISP to respond to requests :-(

PS. What resources are availble on the net on configuring and running a Linux IPChains firewall ? (other that the HOWTO of course :-) )

Eugene van Zyl

