Yep... IPTABLES == IPCHAINS on Massive Steroids
You get three TYPES of tables each possible of doing CHAINS... plus you can apply them PRE-ROUTING or POST-ROUTING... AWESOME...
And... AND... it is tremendously more scalable... it is actually less processor intensive as well...
For IPTABLES, you can do SNAT, DNAT, plain-ole NAT, MASQUERADING, Virtual Address Forwarding, Port forwarding, Address Mapping... defaults can be used to be Open - Except or Closed - Except... it is Stateful (wonderful there) and even that can be turned off... logging has 7 settings (no logging to "OHMYGAWD my 1TiB LOG Volume is Full Already in 20 minutes" setting)
Overall it can make traffic do anything you REALLY want it to do.
b4k4^2
[link|mailto:curley95@attbi.com|greg] - Grand-Master Artist in IT |
[link|http://www.iwethey.org/ed_curry/|REMEMBER ED CURRY!] [link|http://pascal.rockford.com:8888/SSK@kQMsmc74S0Tw3KHQiRQmDem0gAIPAgM/edcurry/1//|ED'S GHOST SPEAKS!] |
[link|http://www.eweek.com/article2/0,3959,857673,00.asp|Writing on wall, Microsoft to develop apps for Linux by 2004] |
Heimatland Geheime Staatspolizei reminds: These [link|http://www.whitehouse.gov/pcipb/cyberspace_strategy.pdf|Civilian General Orders], please memorize them. "Questions" will be asked at safety checkpoints. |