LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-20-2004, 08:21 PM   #1
hoover93
Member
 
Registered: Aug 2003
Distribution: RedHat 9, SuSE 9.2
Posts: 49

Rep: Reputation: 15
stand-alone firewall box?


I have a small office network with a DSL connection to the internet. The phone company provides us with a router that provides NAT but I'm told relying on a NAT router as a firewall is weak. On the internal LAN we have a RedHat Samba server. We do not offer any public services (HTTP, FTP, Email, etc.) to be concerned about allowing outside traffic.

If I want to beef up our firewall security should I add a second NIC to the Samba server and also use it as a Linux firewall? Or, is it better to build a separate box to act as a Linux firewall?

Not being a security guru, I didn't know if adding a second NIC and IP masquerading on the Samba box would make it more vulnerable to internet attack.

Does if matter? If the Samba box is setup correctly, would it drop any and all unwanted packets before they hit the internal network? If the stand-alone box is better, what kind of hardware requirements are needed to deploy an older computer as a non-GUI firewall? I've read that Linux can be used to resurrect old hardware in a case like this.

Any advice would be appreciated.
 
Old 10-21-2004, 02:19 AM   #2
RandomLinuxNewb
Member
 
Registered: Oct 2003
Distribution: Slackware
Posts: 101

Rep: Reputation: 15
It would be best to build a firewall only box. You could use the samba box but a firewall should be doing 1 thing and 1 thing only.... firewalling . The ammount of computer you need depends on the ammount of traffic your office makes, since your using a DSL connection you should be safe with just about any old box you have sitting around. I wouldn't buy anything above a Pentium 2 (if you have to buy). Pentium 133Mhz work fine, my smoothwall setup is run on an old HP P3 Celeron 533 with 128MB of ram. This is over kill but it's all I had sitting around.

There are lots of firewall only version's of linux floating around. I'm using smoothwall, I hear that IPCop is good too (based on smoothwall).

Last edited by RandomLinuxNewb; 10-21-2004 at 02:20 AM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Firewall Box Centinul Linux - Security 10 07-24-2005 03:23 AM
XP Box won't connect to internet thru RH9 Box (firewall/dhcpd), it can only ping fire Rhapsodic Linux - Networking 4 07-10-2004 03:02 PM
Slackware 9.1 firewall box svarreby Linux - Security 3 04-04-2004 06:10 PM
MSN through firewall box ZaphyR Linux - Security 2 12-09-2003 10:17 AM
xfs Daemon on a Firewall Box g_goblin Linux - Security 1 11-28-2002 04:35 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 09:42 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration