Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #198971

Re: Debian 9 network management

From Alessandro Vesely <vesely@tana.it>
Newsgroups linux.debian.user
Subject Re: Debian 9 network management
Date 2018-08-18 11:30 +0200
Message-ID <wo5Iu-3eX-3@gated-at.bofh.it> (permalink)
References <wmCSd-sQ-9@gated-at.bofh.it> <wmXDj-48r-1@gated-at.bofh.it> <wnnxL-2Bz-11@gated-at.bofh.it> <wnpgd-3DQ-1@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On Thu 16/Aug/2018 14:02:08 +0200 Reco wrote:
> On Thu, Aug 16, 2018 at 12:04:28PM +0200, Alessandro Vesely wrote:
>> On Wed 15/Aug/2018 08:31:32 +0200 mick crane wrote:
>>> 
>>> I too have been wondering about this and the wiki seems clear.
>>> https://wiki.debian.org/NetworkConfiguration#Setting_up_an_Ethernet_Interface
>> 
>> However, that doesn't cover how to properly coordinate setting up IP links,
>> firewall, NAT, and netfilter daemons.
> 
> If you're using userspace daemons for netfilter then you're doing it
> wrong. For instance, it has forced non-exsistent distinction between the
> firewall, NAT and netfilter in your e-mail.
> 
> All these are merely the state of running kernel, and while you
> certainly need userspace for configuring them, there's no need for any
> userspace running for these things to function.

A netfilter queue daemon runs in userspace, but that doesn't make much of a
difference.  The point is in what order things are configured/ enabled, and
which files do you have to edit to check or change the corresponding parameters.

>> IIRC it is possible, but difficult to make and maintain, and seemingly
>> fragile.
> 
> A difficulty is in the eye of the beholder.

So is his/ her learning curve, especially in a system where network management
leans toward casual laptop users rather than server admins —and rightly so.

In any case, a sysadmin has to learn the syntax of say, sysctl, ip, iptables,
vconfig, modprobe, and the like.  Hence, just running the right sequence of
(kernel configuration) commands is more straightforward than trying to discover
how to have them run in the same sequence indirectly, by properly setting a
number of configuration files, methinks.  In addition, the semantics of high
level configuration files seems to be more likely to change across releases
than that of lower level commands.

Best
Ale
-- 

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Debian 9 network management Remigio <linoreale@gmail.com> - 2018-08-14 10:30 +0200
  Re: Debian 9 network management Dan Ritter <dsr@randomstring.org> - 2018-08-14 22:30 +0200
    Re: Debian 9 network management Jude DaShiell <jdashiel@panix.com> - 2018-08-15 05:20 +0200
    Re: Debian 9 network management Remigio <linoreale@gmail.com> - 2018-08-20 08:10 +0200
  Re: Debian 9 network management mick crane <mick.crane@gmail.com> - 2018-08-15 08:40 +0200
    Re: Debian 9 network management Alessandro Vesely <vesely@tana.it> - 2018-08-16 12:20 +0200
      Re: Debian 9 network management Zenaan Harkness <zenaan@freedbms.net> - 2018-08-16 12:30 +0200
        Re: Debian 9 network management <tomas@tuxteam.de> - 2018-08-16 12:30 +0200
      Re: Debian 9 network management Reco <recoverym4n@gmail.com> - 2018-08-16 14:10 +0200
        Re: Debian 9 network management Fekete Tamás <fektom@gmail.com> - 2018-08-16 20:10 +0200
        Re: Debian 9 network management Alessandro Vesely <vesely@tana.it> - 2018-08-18 11:30 +0200
          Re: Debian 9 network management Reco <recoverym4n@gmail.com> - 2018-08-18 12:20 +0200

csiph-web