LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 06-02-2008, 07:35 AM   #1
jose_tk
LQ Newbie
 
Registered: Sep 2007
Location: New Delhi
Distribution: Ubuntu, SUSE, RedHat
Posts: 15

Rep: Reputation: 0
firewall suggestions


Hi there,

My company is going to launch a Data Center which consists of 30+ Linux Servers (RH and CentOS). There are two connections getting from the ISP in which one will go the the Data Center and the other goes to the Corporate Network. We need to add redundancy to the Data Center connectivity by adding two firewall (if one fails other has to take on).

My question is which should be the ideal Firewall to go for?
Which is better if acting independently and which is better one for a firewall HA? We are open to iptables based or FreeBSD based Firewalls.

Kindly share your suggestions and thoughts.

Thankyou for your time
Jose
 
Old 06-02-2008, 08:20 AM   #2
Tux-Slack
Member
 
Registered: Nov 2006
Location: Slovenia
Distribution: Slackware 13.37
Posts: 511

Rep: Reputation: 37
I've never used any of these "auto configurational" firewalls, but in your case I would chose m0n0wall.
 
Old 06-02-2008, 09:01 AM   #3
Nathanael
Member
 
Registered: May 2004
Location: Karlsruhe, Germany
Distribution: debian, gentoo, os x (darwin), ubuntu
Posts: 940

Rep: Reputation: 33
for a company you could use some commercial product, such as astaro (http://www.astaro.de http://www.astaromarket.de) or gibraltar (http://www.gibraltar.at)

i personally though always prefere raw iptables.
 
Old 06-02-2008, 10:34 AM   #4
lsteacke
Member
 
Registered: Jul 2007
Distribution: Ubuntu
Posts: 99

Rep: Reputation: 16
You might also want to consider shorewall. Its a config based firewall, but translates the configs into iptables.

http://www.shorewall.net
 
Old 06-02-2008, 01:27 PM   #5
salasi
Senior Member
 
Registered: Jul 2007
Location: Directly above centre of the earth, UK
Distribution: SuSE, plus some hopping
Posts: 4,070

Rep: Reputation: 897Reputation: 897Reputation: 897Reputation: 897Reputation: 897Reputation: 897Reputation: 897
Quote:
Originally Posted by jose_tk View Post
My company is going to launch a Data Center which consists of 30+ Linux Servers (RH and CentOS).
In which case, being as this is quite a professional operation, presumably you will have asked your security specialist and your networking specialist (maybe this is one person) their preferences.

If you don't have that kind of expertise, in house, maybe you should be considering a solution like Cisco, Bay Networks, Juniper, etc, etc because without the relevant expertise you'll want something that is easy to administer.

Failing that, you might consider one of the stand-alone firewall distros, like Astaro, IPCop, whatever ClarkConnect is called these days. Even here, you would be advised to have someone who knows what they are doing, so someone should go on an appropriate course.

Failing that, there is the 'roll your own' approach Most of the GUI firewalls are just front ends to Iptables, etc, so don't add any new capabilities, but arguably make configuration easier for newbies. However, the person doing this should in no way be a newbie. We all make mistakes or do things sub-optimally the first time through and do you want to risk your entire data centre operation on the chance of how your newbie's errors affect your customers?

So, if you get to this stage, you really, really need someone who knows what they are doing, whether that means hiring an expert for a while or training your own. Given that for this you need an expert, I'm not clear why you are asking a bunch of miscellaneous strangers, some of whom may lie or indulge in black-hatted behaviour for amusement.
 
Old 06-02-2008, 11:13 PM   #6
requiem
LQ Newbie
 
Registered: Aug 2003
Location: Kentucky
Distribution: Ubuntu, Fedora
Posts: 3

Rep: Reputation: 0
Smoothwall

I'd check this out: SmoothWall I've heard good things about this in the past. Check out the feature comparison chart on the page.
 
Old 06-02-2008, 11:54 PM   #7
hemi_426
Member
 
Registered: Apr 2008
Location: KSA-jeddah
Distribution: CentOS, gentoo, slackware
Posts: 80

Rep: Reputation: 15
im with Slasi
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Firewall Suggestions sbabcock23 Linux - Security 8 06-10-2007 02:59 AM
Suggestions for a CD based router/firewall distro ConcreteClam Linux - Networking 3 05-25-2004 03:59 PM
NIS/NFS Thru or Around Firewall - Suggestions? Jefficus Linux - Networking 2 03-25-2004 05:46 PM
Router/firewall suggestions phoenix76 Linux - Security 3 11-30-2003 10:26 PM
router of firewall suggestions Stephanie Linux - General 3 07-28-2001 09:24 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 01:03 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration