[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#656343: ITP: ipset -- administration tool for kernel IP sets



Package: wnpp
Severity: wishlist
Owner: "Neutron Soutmun" <neo.neutron@gmail.com>

* Package name    : ipset
  Version         : 6.11
  Upstream Author : Jozsef Kadlecsik <kadlec@blackhole.kfki.hu>
* URL             : http://ipset.netfilter.org/
* License         : GPL
  Programming Lang: C
  Description     : administration tool for kernel IP sets

IP sets are a framework inside the Linux 2.4.x and 2.6.x kernel which can be
administered by the ipset(8) utility. Depending on the type, currently an
IP set may store IP addresses, (TCP/UDP) port numbers or IP addresses with
MAC addresses in a  way which ensures lightning speed when matching an
entry against a set.

If you want to

 * store multiple IP addresses or port numbers and match against the
   entire collection using a single iptables rule.
 * dynamically update iptables rules against IP addresses or ports without
   performance penalty.
 * express complex IP address and ports based rulesets with a single
   iptables rule and benefit from the speed of IP sets.

then IP sets may be the proper tool for you.

Note: As the package ipset has been removed from the Debian archive
  unstable with the reason as decribed in http://bugs.debian.org/651790
  which "the ipset fails to build against current kernel; no response from
  maintainer".

  But it's not a problem now as the ipset already included in the recent kernel   , kernel 3.1 in wheezy/sid and also the 3.2 in experimental are fine,
  no needs to build any modules.

  Therefore, I intend to package and has already started (based on the latest
  ipset package that was removed and more updates). The package could
  be uploaded soon.

Attachment: signature.asc
Description: Digital signature


Reply to: