Re: loading huge number of rules in iptables (blocklist)
On Wed, Mar 21, 2007 at 04:39:57PM -0400, H.S. wrote:
> I am not going to follow up on my current method. A better one is
> definitely needed.
Googling on the shorewall home page yielded the following:
http://www.shorewall.net/ipsets.html
...
...Ipsets provide an effecient way to represent large sets
of addresses and you can maintain the lists without the need to
restart or even refresh your Shorewall configuration.
Ken
--
Ken Irving
Reply to: