Revision 1 as of 2008-08-19 17:53:00

Clear message

Not ready for human consumption, I'll remove this notice and resume work on this article when I get back from SOC - [LAW]


The devil has a name, and it is ucc-fw. This article aspires to be a reference manual for the UCC firewall.

Not just a firewall

ucc-fw is located on madako in /etc/init.d/ and at time of writing weighs in at nearly 700 lines of arcane iptables commands and cryptic comments, and is responsible for keeping the baddies out. It is also responsible for keeping costs down by making sure the right data goes out the right link, NAT for the Silk link, and a lot of other things the reasons for which will become apparent as you become familiar with the way information flows in and out of the club.