2003-12-15 04:49:39 +01:00
|
|
|
|
<?xml version="1.0" encoding="UTF-8"?>
|
|
|
|
|
<!DOCTYPE article PUBLIC "-//OASIS//DTD DocBook XML V4.2//EN"
|
|
|
|
|
"http://www.oasis-open.org/docbook/xml/4.2/docbookx.dtd">
|
|
|
|
|
<article>
|
|
|
|
|
<articleinfo>
|
|
|
|
|
<title>Quotes from Users</title>
|
|
|
|
|
|
|
|
|
|
<author>
|
|
|
|
|
<firstname>Tom</firstname>
|
|
|
|
|
|
|
|
|
|
<surname>Eastep</surname>
|
|
|
|
|
</author>
|
|
|
|
|
|
|
|
|
|
<copyright>
|
|
|
|
|
<year>2003</year>
|
|
|
|
|
|
|
|
|
|
<holder>Thomas M Eastep</holder>
|
|
|
|
|
</copyright>
|
|
|
|
|
|
|
|
|
|
<pubdate>2003-07-01</pubdate>
|
|
|
|
|
</articleinfo>
|
|
|
|
|
|
2003-12-15 19:11:53 +01:00
|
|
|
|
<section>
|
2003-12-15 04:49:39 +01:00
|
|
|
|
<title>What Users are saying...</title>
|
|
|
|
|
|
|
|
|
|
<itemizedlist>
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>"I have fought with IPtables for untold hours. First I tried
|
|
|
|
|
the SuSE firewall, which worked for 80% of what I needed. Then
|
|
|
|
|
gShield, which also worked for 80%. Then I set out to write my own
|
|
|
|
|
IPtables parser in shell and awk, which was a lot of fun but never got
|
|
|
|
|
me past the "hey, cool" stage. Then I discovered Shorewall.
|
|
|
|
|
After about an hour, everything just worked. I am stunned, and very
|
|
|
|
|
grateful" -- ES, Phoenix AZ, USA. </para>
|
|
|
|
|
</listitem>
|
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>"The configuration is intuitive and flexible, and much
|
|
|
|
|
easier than any of the other iptables-based firewall programs out
|
|
|
|
|
there. After sifting through many other scripts, it is obvious that
|
|
|
|
|
yours is the most well thought-out and complete one available." --
|
|
|
|
|
BC, USA </para>
|
|
|
|
|
</listitem>
|
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>"I just installed Shorewall after weeks of messing with
|
|
|
|
|
ipchains/iptables and I had it up and running in under 20
|
|
|
|
|
minutes!" -- JL, Ohio</para>
|
|
|
|
|
</listitem>
|
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>"My case was almost like [the one above]. Well. instead of
|
|
|
|
|
'weeks' it was 'months' for me, and I think I needed
|
|
|
|
|
two minutes more:</para>
|
|
|
|
|
|
|
|
|
|
<itemizedlist>
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>One to see that I had no Internet access from the firewall
|
|
|
|
|
itself.</para>
|
|
|
|
|
</listitem>
|
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>Other to see that this was the default configuration, and it
|
|
|
|
|
was enough to uncomment a line in /etc/shorewall/policy.</para>
|
|
|
|
|
</listitem>
|
|
|
|
|
</itemizedlist>
|
|
|
|
|
</listitem>
|
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>Minutes instead of months! Congratulations and thanks for such a
|
|
|
|
|
simple and well documented thing for something as huge as
|
|
|
|
|
iptables." -- JV, Spain. </para>
|
|
|
|
|
</listitem>
|
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>"I downloaded Shorewall 1.2.0 and installed it on Mandrake
|
|
|
|
|
8.1 without any problems. Your documentation is great and I really
|
|
|
|
|
appreciate your network configuration info. That really helped me out
|
|
|
|
|
alot. THANKS!!!" -- MM. </para>
|
|
|
|
|
</listitem>
|
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>"[Shorewall is a] great, great project. I've used/tested
|
|
|
|
|
may firewall scripts but this one is till now the best." -- B.R,
|
|
|
|
|
Netherlands </para>
|
|
|
|
|
</listitem>
|
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>"Never in my +12 year career as a sys admin have I witnessed
|
|
|
|
|
someone so relentless in developing a secure, state of the art, safe
|
|
|
|
|
and useful product as the Shorewall firewall package for no cost or
|
|
|
|
|
obligation involved." -- Mario Kerecki, Toronto </para>
|
|
|
|
|
</listitem>
|
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>"one time more to report, that your great shorewall in the
|
|
|
|
|
latest release 1.2.9 is working fine for me with SuSE Linux 7.3! I now
|
|
|
|
|
have 7 machines up and running with shorewall on several versions -
|
|
|
|
|
starting with 1.2.2 up to the new 1.2.9 and I never have encountered
|
|
|
|
|
any problems!" -- SM, Germany </para>
|
|
|
|
|
</listitem>
|
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>"You have the best support of any other package I've
|
|
|
|
|
ever used." -- SE, US </para>
|
|
|
|
|
</listitem>
|
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>"Because our company has information which has been
|
|
|
|
|
classified by the national government as secret, our security
|
|
|
|
|
doesn't stop by putting a fence around our company. Information
|
|
|
|
|
security is a hot issue. We also make use of checkpoint firewalls, but
|
|
|
|
|
not all of the internet servers are guarded by checkpoint, some of
|
|
|
|
|
them are running....Shorewall." -- Name withheld by request,
|
|
|
|
|
Europe </para>
|
|
|
|
|
</listitem>
|
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>"thanx for all your efforts you put into shorewall - this
|
|
|
|
|
product stands out against a lot of commercial stuff i´ve been working
|
|
|
|
|
with in terms of flexibillity, quality & support" -- RM,
|
|
|
|
|
Austria </para>
|
|
|
|
|
</listitem>
|
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>"I have never seen such a complete firewall package that is
|
|
|
|
|
so easy to configure. I searched the Debian package system for
|
|
|
|
|
firewall scripts and Shorewall won hands down." -- RG, Toronto
|
|
|
|
|
</para>
|
|
|
|
|
</listitem>
|
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>"My respects... I've just found and installed Shorewall
|
|
|
|
|
1.3.3-1 and it is a wonderful piece of software. I've just sent
|
|
|
|
|
out an email to about 30 people recommending it. :-) </para>
|
|
|
|
|
|
|
|
|
|
<para>While I had previously taken the time (maybe 40 hours) to really
|
|
|
|
|
understand ipchains, then spent at least an hour per server
|
|
|
|
|
customizing and carefully scrutinizing firewall rules, I've got
|
|
|
|
|
shorewall running on my home firewall, with rulesets and policies that
|
|
|
|
|
I know make sense, in under 20 minutes." -- RP, Guatamala </para>
|
|
|
|
|
</listitem>
|
|
|
|
|
</itemizedlist>
|
2003-12-15 19:11:53 +01:00
|
|
|
|
</section>
|
|
|
|
|
</article>
|