Rules in config file
lists at alpha-force.net
Wed Aug 10 14:18:04 CEST 2005
Would it be possible to somehow disable changing iptables rules from scripts and enable changing only from config file, which loading would be protected by special password defined in kernel? Or even better, your could preset iptables rules in kernel. That rules would be unchangeable.
I think this would improve Linux firewall security on systems with complex and tight rules.
More information about the netfilter