What's new

The optimum way to use iptables and ipsets

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

spalife

Regular Contributor
Started a general discussion thread so that everyone
can pitch in with their opinions about the ways
which using iptables and ipsets can benefit the end user.
 
Not to inflame anyone
just partially quoted the current discussion,
so that we can have a productive use of this thread.

The initial quotes for historical purposes are available
on this thread

kvic said:
it's more efficient to use "filter" rather than "raw" tables

Adamm said:
Blocking a packet in raw means not only are there 4 less layers of processing by the kernel, but there's no overhead of conntracking.
 
Last edited:

Latest threads

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top