LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-14-2014, 05:02 AM   #1
a989
LQ Newbie
 
Registered: Jan 2014
Posts: 2

Rep: Reputation: Disabled
Need a firewall software


Hi all,
I need a simple to use firewall software in a 100 employee environment.
Firewall should block unnecessary websites, keywords, videos, images, any intrusion as per users and groups (eg: teachers and students). Bandwidth shaping would be a plus.
Please suggest me some.
 
Old 01-14-2014, 05:22 AM   #2
TenTenths
Senior Member
 
Registered: Aug 2011
Location: Dublin
Distribution: Centos 5 / 6 / 7
Posts: 3,475

Rep: Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553
Go for a hardware or "appliance" solution, Fortigate / FortiOS is good.

Yes, there will be people who are now going to say "use Linux, use SQUID, iptables, etc." which is fine if you want to go down the do it yourself path.

I've a Fortigate FC80 here with about 70 users behind it, and if I want to block "File Swapping" or "Proxy Avoidance" then I define the policy and tick the boxes in the GUI. These lists are updated and maintained by Fortigate so I don't have to keep updating them etc.

For bandwidth shaping, I've 2Mb that's reserved for phones and for web use my general users are in a shared 4Mb and "executive" users are in a shared 8Mb.

If you're determined to go down the "free software" route then SQUID and iptables will be your starting points.
 
Old 01-14-2014, 05:32 AM   #3
druuna
LQ Veteran
 
Registered: Sep 2003
Posts: 10,532
Blog Entries: 7

Rep: Reputation: 2405Reputation: 2405Reputation: 2405Reputation: 2405Reputation: 2405Reputation: 2405Reputation: 2405Reputation: 2405Reputation: 2405Reputation: 2405Reputation: 2405
@TenTenths: Just curious:

What is the difference between a do it yourself path for iptables/squid/etc and a do it yourself path for Fortigate / FortiOS? Seems to me that both have a (possible steep) learning curve and using Fortigate / FortiOS needs specialized equipment.

Don't get me wrong, your solution might be a good option but the reason why isn't too clear from your post.
 
Old 01-14-2014, 05:44 AM   #4
TenTenths
Senior Member
 
Registered: Aug 2011
Location: Dublin
Distribution: Centos 5 / 6 / 7
Posts: 3,475

Rep: Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553
Need a firewall software

Fortigate is a hardware firewall / router device which offers content filtering, website blocking, email and webpage anti-virus scanning, DHCP, VPN server, etc. all with a web interface.

Sometimes paying for a device is more cost / time effective than having a person spend days or weeks building a solution.
 
1 members found this post helpful.
Old 01-14-2014, 05:44 AM   #5
a989
LQ Newbie
 
Registered: Jan 2014
Posts: 2

Original Poster
Rep: Reputation: Disabled
Thank you for your reply.
I am looking for a software appliance rather than hardware solution.
Of course, not willing to compile squid, iptables, IPS, etc. from scratch.
My requirement is full control on content filtering and intrusion prevention with simple web interface.
I found some open source software appliances projects giving it a try on my virtual machines.
Like:

pfsense
simplewall
endian
smoothwall
clearOS
monowall

I will share my experience with these appliances tests soon.
Thank you guys.
 
Old 01-14-2014, 06:01 AM   #6
ericson007
Member
 
Registered: Sep 2004
Location: Japan
Distribution: CentOS 7.1
Posts: 735

Rep: Reputation: 154Reputation: 154
I currently run pfsense as a virtual router and firewall and vpn server with snort.

Works really well, 4 cores 4gb ram assigned, wan nic directly passed, dmz, lan, vpn on bridge interface.

Works but have never tried close to 100 users on it. I would rather go dedicated hardware for that many users depending on your throughput requirements.

On my system it saturates 50mpbs down and 25mpbs up that i have with ample cpu and ram left.

My next purchase is a i350 4port intel nic to get rid of the bridge assigning a port to each vm using sr-iov

Last edited by ericson007; 01-14-2014 at 06:38 AM.
 
Old 01-14-2014, 06:10 AM   #7
TenTenths
Senior Member
 
Registered: Aug 2011
Location: Dublin
Distribution: Centos 5 / 6 / 7
Posts: 3,475

Rep: Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553
Quote:
Originally Posted by a989 View Post
I found some open source software appliances projects giving it a try on my virtual machines.
If you've the time and resources for the testing etc. then great! Let us know how you get on as it'll help others

Quote:
Originally Posted by ericson007 View Post
Works but have never tried close to 100 users on it. I would rather go dedicated hardware for that many users depending on your throughput requirements.
Any recent hardware will be able to keep up with throughput as generally the WAN link will be the bottleneck.

We also have Juniper SSG firewalls with a web management interface but the Fortigate device is a bit easier to use and intuitive. We had it unpackaged and running our filtering requirements in about 1 day.
 
Old 01-14-2014, 07:00 AM   #8
ericson007
Member
 
Registered: Sep 2004
Location: Japan
Distribution: CentOS 7.1
Posts: 735

Rep: Reputation: 154Reputation: 154
One thing to remember with virtual routers is that yes they may work fine and get limited by wan, but if the vm host has many vms then it can cost performance deductions on other virtual machines. So virtual routing is great but a double edge sword at the same time.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Firewall Software, What do you use and how well do you like it? agentc0re Slackware 7 07-04-2007 12:17 PM
router billion 5102 has firewall and software firewall tests aus9 Linux - Security 6 12-31-2006 10:09 PM
Software firewall. greenthing Linux - Security 1 04-15-2005 09:58 AM
Best software firewall proton666 Linux - Newbie 1 12-03-2004 04:06 PM
Software Firewall PionexUser Linux - Newbie 1 07-13-2003 10:45 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:33 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration