大牛 Michael Rash 新作,
www.netfilter.org 推荐, No Starch Press, 2007年9月出版.
focuses heavily on what is possible from an intrusion detection and prevention standpoint within the context of iptables.
for more info, please see:
http://www.cipherdyne.org/LinuxFirewalls