|
|
Log in / Subscribe / Register

The Grumpy Editor's guide to surviving the systemd debate

The Grumpy Editor's guide to surviving the systemd debate

Posted Nov 13, 2014 14:10 UTC (Thu) by anselm (subscriber, #2796)
In reply to: The Grumpy Editor's guide to surviving the systemd debate by dps
Parent article: The Grumpy Editor's guide to surviving the systemd debate

Paranoid? If the init process on your firewall does anything more than set up networking and iptables and then exit, then you're not paranoid enough. Who needs userspace processes on a firewall at all when a properly configured kernel on its own will do everything that's necessary?


to post comments

The Grumpy Editor's guide to surviving the systemd debate

Posted Nov 13, 2014 14:49 UTC (Thu) by JGR (subscriber, #93631) [Link]

Changing the firewall rules at run time, logging/reporting, various forms of error handling and recovery (network goes down then up after init, etc.) and so on generally need some form of user-space.
It's quite possible implement these without sacrificing security.

The Grumpy Editor's guide to surviving the systemd debate

Posted Nov 13, 2014 20:15 UTC (Thu) by dlang (guest, #313) [Link]

real firewalls are more than just packet filtering, no matter what Cisco and Checkpoint try to tell you.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds