{"title":"The research and implementation of transplanting the Iptables/Netfilter to an IXP2400 based firewall system","authors":"X. Dou, Jia Li, Ling Zhang, Shou-bin Dong","doi":"10.1109/ICESS.2005.95","DOIUrl":null,"url":null,"abstract":"NP based firewall research has attracted intensive attention. This paper presents a methodology to establish a rule parser and a command-line interface for a firewall system based on IXP2400 utilizing the existing code of the popular Iptables/Netfilter software. We describe how to modify the user-space code of Iptables and how to transplant the kernel code of Netfilter. We also explain the implementation of address transforming between the virtual address used by the Linux kernel and the physical address used by the ME.","PeriodicalId":360757,"journal":{"name":"Second International Conference on Embedded Software and Systems (ICESS'05)","volume":"23 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2005-12-16","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Second International Conference on Embedded Software and Systems (ICESS'05)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICESS.2005.95","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3
Abstract
NP based firewall research has attracted intensive attention. This paper presents a methodology to establish a rule parser and a command-line interface for a firewall system based on IXP2400 utilizing the existing code of the popular Iptables/Netfilter software. We describe how to modify the user-space code of Iptables and how to transplant the kernel code of Netfilter. We also explain the implementation of address transforming between the virtual address used by the Linux kernel and the physical address used by the ME.