LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 07-18-2005, 06:16 AM   #1
Centinul
Member
 
Registered: Jun 2005
Distribution: Gentoo
Posts: 552

Rep: Reputation: 30
Firewall Box -- Distro Choice Question


I'm thinking of using a Celeron 500mHz, 64MB Ram, 3.2Gb Harddrive as a Firewall Box. What do you suggest that I run for a distribution that won't slow this old machine down? Thanks!

Last edited by Centinul; 07-18-2005 at 07:13 AM.
 
Old 07-18-2005, 08:49 AM   #2
peter_robb
Senior Member
 
Registered: Feb 2002
Location: Szczecin, Poland
Distribution: Gentoo, Debian
Posts: 2,458

Rep: Reputation: 48
Depending on how familiar you are with making a custom kernel or building packages, of the major names, you could try Slackware, Debian, even Gentoo.
I suggest these coz they don't automatically drown you with gui tools or unecessary packages.
I would avoid Fedora, Mandrake/Mandriva and SuSe coz you won't get any easy upgrade option, especially when the distro version jumps. Package maintenance will always be an issue with a firewall.

If you just want a quick and easy firewall with some tweaking, look at www.smoothwall.org
 
Old 07-18-2005, 08:52 AM   #3
Centinul
Member
 
Registered: Jun 2005
Distribution: Gentoo
Posts: 552

Original Poster
Rep: Reputation: 30
I've never built a custom kernel but it would provide a good opportunity for me to learn a few things. How would you suggest I go about it? Also, would those distro's you suggested run on the machine specs I gave?

Also one other quick question. Do I have to rebuild the custom kernel everytime I upgrade? It sounds like a lot of work.

Last edited by Centinul; 07-18-2005 at 08:54 AM.
 
Old 07-18-2005, 09:07 AM   #4
peter_robb
Senior Member
 
Registered: Feb 2002
Location: Szczecin, Poland
Distribution: Gentoo, Debian
Posts: 2,458

Rep: Reputation: 48
You would only need to redo a kernel to add features not in earlier versions, or fix bugs.
They don't take too long to do, so long as you cut out all the unecessary stuff, eg graphics, sound, unused drivers, usb etc.

I suggest reading the http://iptables-tutorial.frozentux.n...-tutorial.html then download and install smoothwall, take a good look and decide how to do the same in a full distro. At this stage I'd recommend Debian Sarge until you get used to building in one fast pc and transferring packages to the slower box. Try to drop in 256MB ram if you can. The more the merrier.. Makes Snort and Squid run faster.
 
Old 07-18-2005, 09:46 AM   #5
Centinul
Member
 
Registered: Jun 2005
Distribution: Gentoo
Posts: 552

Original Poster
Rep: Reputation: 30
I really appreciate the help. I'll take a look at the tutorial ASAP.

Just out of curiousity, will an old slow machine slow down the internet connection speed?


BTW, congrats on 1800th post
 
Old 07-18-2005, 10:09 AM   #6
mhallbiai
Member
 
Registered: Jun 2005
Posts: 96

Rep: Reputation: 16
i dont think it will slow down the connection but that depends on your NICs compared to the rest of your setup. Since most PCs come with at least a 100mb nic nowadays the cable/dsl tend to be the bottleneck due to the restrictions placed by ISPs. i have an old k6-2 300mhz with 512Mb RAM and a couple 10/100 NICs acting as my firewall with no noticable decrease.

hope this helps
 
Old 07-18-2005, 10:28 AM   #7
peter_robb
Senior Member
 
Registered: Feb 2002
Location: Szczecin, Poland
Distribution: Gentoo, Debian
Posts: 2,458

Rep: Reputation: 48
ram is the answer to speed.. the more ram, the more conntrack entries, the less page file swapping.

Actually, once the box is running, you can test the throughput with a large file. Test tcp and udp, and also the drivers. I have several lethargic Realtek chipsets under standard drivers that are v.quick under basic drivers.. Time to recompile and test some more..
 
Old 07-18-2005, 10:39 AM   #8
mhallbiai
Member
 
Registered: Jun 2005
Posts: 96

Rep: Reputation: 16
i have to agree with peter_robb on RAM. if you notice you hit swap often then time to increase. in my config and number of systems behind my firewall i usually sit near the top of my ram usage but manage to refrain from swapping. i also have a lot of connection tracking/logging (stave off those ssh intrusion attempts among other things) so your mileage will vary.
 
Old 07-18-2005, 11:13 AM   #9
Centinul
Member
 
Registered: Jun 2005
Distribution: Gentoo
Posts: 552

Original Poster
Rep: Reputation: 30
I'm definitely really new to this and linux in general. I'm just trying to soak it all in. I think it would be a good exercise for me to learn to setup a firewall because I really hit two birds with one stone. 1. I get to compile a kernel 2. I learn more about how the internet / networking really works.

Thanks!
 
Old 07-20-2005, 09:51 PM   #10
auditek747
Member
 
Registered: Feb 2004
Location: Ohio, USA
Distribution: Arch Linux
Posts: 464

Rep: Reputation: 30
A slow machine won't hurt you're internet any.
My current firewall is a P166 with 32meg ram running "FloppyFW"
and it's fine.
I'm currently testing a 450celeron machine with 128meg ram.
It's running Slackware 10.1 with KDE 3.3.x . It's a little slow but not bad for
every day stuff. I'm using "Firestarter" to set up firewall and routing.

http://www.zelow.no/floppyfw/

http://www.fs-security.com/
 
Old 07-24-2005, 03:23 AM   #11
floppywhopper
Member
 
Registered: Aug 2004
Location: Western Australia
Distribution: Mageia , Centos
Posts: 643
Blog Entries: 2

Rep: Reputation: 136Reputation: 136
I'm using a Pentium II 350Mhz with 64 M ram, 3 Gb Hdd
on IP Cop
it runs OK
I used to run Smoothwall 2.0
and I'm thinking of switching back to it

floppy
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
stand-alone firewall box? hoover93 Linux - Security 1 10-21-2004 02:19 AM
XP Box won't connect to internet thru RH9 Box (firewall/dhcpd), it can only ping fire Rhapsodic Linux - Networking 4 07-10-2004 03:02 PM
Slackware 9.1 firewall box svarreby Linux - Security 3 04-04-2004 06:10 PM
MSN through firewall box ZaphyR Linux - Security 2 12-09-2003 10:17 AM
xfs Daemon on a Firewall Box g_goblin Linux - Security 1 11-28-2002 04:35 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:46 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration