IP sets are a framework inside the Linux kernel netfilter subsystem, which can be administered by the ipset utility. Depending on the type, currently an IP set may store IP addresses, (TCP/UDP) port numbers or IP addresses with MAC addresses in a way, which ensures lightning speed when matching an entry against a set. Features: * store multiple IP addresses or port numbers and match against the collection by iptables at one swoop; * dynamically update iptables rules against IP addresses or ports without performance penalty; * express complex IP address and ports based rulesets with one single iptables rule and benefit from the speed of IP sets
CC'ing some people who may have a passing interest.
*** Bug 196234 has been marked as a duplicate of this bug. ***
The Fedora 16 kernel (linux-3.0) will have support for ipset. Here are libmnl and ipset test packages for Fedora 16: http://twoerner.fedorapeople.org/ipset/ http://twoerner.fedorapeople.org/libmnl/