Consider using a 2.4 kernal so that you can take advantage of iptables which is easier and more powerful. You can do a lot of things in iptable much more simply than ipchains, and since it is session based (unlike ipchains which is sessionless) it can detect some attacks much better than ipchains.
|