X-Original-To: alpine-devel@lists.alpinelinux.org Delivered-To: alpine-devel@mail.alpinelinux.org Received: from jeremythomerson.com (unknown [74.117.189.39]) by mail.alpinelinux.org (Postfix) with ESMTP id 653FBDC1609 for ; Tue, 3 Jan 2012 17:45:41 +0000 (UTC) Received: from mail-vx0-f182.google.com (mail-vx0-f182.google.com [209.85.220.182]) by jeremythomerson.com (Postfix) with ESMTP id E560E1C929 for ; Tue, 3 Jan 2012 12:23:00 -0600 (CST) Received: by vcbfk1 with SMTP id fk1so21852916vcb.13 for ; Tue, 03 Jan 2012 09:45:40 -0800 (PST) Received: by 10.52.67.179 with SMTP id o19mr8082215vdt.106.1325612740220; Tue, 03 Jan 2012 09:45:40 -0800 (PST) X-Mailinglist: alpine-devel Precedence: list List-Id: Alpine Development List-Unsubscribe: List-Post: List-Help: List-Subscribe: MIME-Version: 1.0 Reply-To: jeremy@thomersonfamily.com Received: by 10.220.178.130 with HTTP; Tue, 3 Jan 2012 09:45:19 -0800 (PST) In-Reply-To: References: From: Jeremy Thomerson Date: Tue, 3 Jan 2012 12:45:19 -0500 Message-ID: Subject: Re: [alpine-devel] Alpine Wall for firewall management To: Kaarle Ritvanen Cc: alpine-devel@lists.alpinelinux.org Content-Type: multipart/alternative; boundary=20cf307ca6307d964404b5a34407 --20cf307ca6307d964404b5a34407 Content-Type: text/plain; charset=ISO-8859-1 On Fri, Dec 30, 2011 at 9:08 AM, Kaarle Ritvanen < kaarle.ritvanen@datakunkku.fi> wrote: > Hello, > > We have a new firewall management framework under early development. > Please check out the draft specification here and provide your comments: > > http://wiki.alpinelinux.org/**wiki/Alpine_Wall > > BR, > Kaarle > Not having looked through all of it in great detail, I have a question about the following statement from the wiki: > The back-end will contain functionality for domain name resolution. In the > data model, hosts of groups thereof can be identified by their domain > names. The back-end will resolve these to IP addresses, which will be > stored in the target files, so there will be no need to resolve anything > when activating the configuration during boot. > At what point does the back-end do the resolution? It seems like it would need to periodically update this since a firewall may run weeks, months, or years with no change and name resolution could change periodically. Will it observe TTL? Overall, the plan looks really good. I'd be curious: will there be a CLI for the functionality, or will it only be in ACF webapp? I typically don't use ACF on my Alpine boxes. I assume without ACF I'll just need to modify the Alpine Wall config files directly? Thanks! Jeremy Thomerson --20cf307ca6307d964404b5a34407 Content-Type: text/html; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable
On Fri, Dec 30, 2011 at 9:08 AM, Kaarle Ritv= anen <kaarle.ritvanen@datakunkku.fi> wrote:
Hello,

We have a new firewall management framework under early development. Please= check out the draft specification here and provide your comments:

= http://wiki.alpinelinux.org/wiki/Alpine_Wall

BR,
Kaarle

Not having looked through all of it in grea= t detail, I have a question about the following statement from the wiki:

The back-end will contain functionality for domain name resolution. In the data model, hosts of groups thereof can be identified by their domain names. The back-end will resolve these to IP addresses, which will be stored in the target files, so there will be no need to resolve anything when activating the configuration during boot.

At what point does the back-end do the resolution?=A0= It seems like it would need to periodically update this since a firewall m= ay run weeks, months, or years with no change and name resolution could cha= nge periodically.=A0 Will it observe TTL?

Overall, the plan looks really good.=A0 I'd be curious: will there = be a CLI for the functionality, or will it only be in ACF webapp?=A0 I typi= cally don't use ACF on my Alpine boxes.=A0 I assume without ACF I'l= l just need to modify the Alpine Wall config files directly?

Thanks!
Jeremy Thomerson
=A0

--20cf307ca6307d964404b5a34407-- --- Unsubscribe: alpine-devel+unsubscribe@lists.alpinelinux.org Help: alpine-devel+help@lists.alpinelinux.org ---