Hello list,
Finally have working firewall rules analysis code up & running. This turns out to be a hard problem! A lot of people have worked out the math, but there are a ton of picky obstacles to applying them to real sets of iptables rules. I hope to flesh out the code over the next few months and am hoping for a release (public open source) soon.