Design and Implementation
sf Firewall Software--a TCP/IP packet filter for Linux
Version 0.1, last edited on 02/04/1996
Table Of Contents
- The Structure of the sf Firewall
- Overview
- The Components
- Packet Handling
- Patching the Linux Kernel
- Description of the Kernel Filter Module Stub
- Interaction between the Components
- Loading the Kernel Filter Module
- Starting the Firewall Daemon--the Firewall Device
- Configuring the Filter Function through the Firewall Device
- Reconfiguring the Filter Function
- Reading the Active Rules from the Firewall Device
- The Firewall Daemon
- Detecting if the Firewall Daemon is already Running
- Signals and the Firewall Pipe
- Starting External Commands
- The Event Mechanism
- Error Handling
- Avoiding Duplicate Log Entries
- Variables and Time-Outs
- Counter Intelligence
- Enhancing the Firewall Daemon
- Adding New Keywords
- Enhancing the Counter Intelligence
- Configuration Data
- Filter Rules
- Notification Structure
- Configuring the Filter
- The Packet Filter
- Address Spoofing
- Fragmentation
- TCP
- Rules
- Log Information
- Configuration and Control Routines
Copyright © 1996 Robert Muchsel and Roland Schmid.
Click here to mail your comments and suggestions.