LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-17-2006, 05:33 AM   #1
eNtoS
Member
 
Registered: Feb 2006
Distribution: slackware, ubuntu, knoppix, backtrack, debian
Posts: 35

Rep: Reputation: 15
which antivirus software for linux gateway?


Hey!

I have an old pentium 3 lying around and i thought i could make some good use of it by turning it into an antivirus/firewall gateway machine. Considering Vista's kernel protection, and its finished RTM copy, such a security gateway might become very useful in the near future...

So my question is what do you guys suggest as a good distro or distro+package to put in between the net and my LAN which should takeover the role of antivirus scanning and firewalling (for infections coming from the internet side)?

Oh and this should preferably be a transparent solution... (but i guess connecting to the net through a proxy running on the gateway should also work as a last resort)...

thx ahead guys!
 
Old 11-17-2006, 05:47 AM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
i'd point you towards ipcop. probably also want the advproxy addons for it to get proper av scanning, url filters and such
 
Old 11-20-2006, 02:54 AM   #3
angopal
LQ Newbie
 
Registered: Nov 2006
Posts: 5

Rep: Reputation: 0
antivirus for linux

why cant we go for iptables... it is better than ipcop rite...
 
Old 11-20-2006, 05:43 AM   #4
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
Quote:
Originally Posted by angopal
why cant we go for iptables... it is better than ipcop rite...
iptables is only a configuration tool for netfilter (the linux firewall)... ipcop, on the other hand, is a complete gateway/firewall distro with all sorts of packages (including iptables)... so it's like comparing apples to oranges...
 
Old 11-20-2006, 07:22 AM   #5
eNtoS
Member
 
Registered: Feb 2006
Distribution: slackware, ubuntu, knoppix, backtrack, debian
Posts: 35

Original Poster
Rep: Reputation: 15
i thought iptables was an integral part of linux networking... but anyways, that just serves as a firewall (n my router can do that), what i need is virus scanning...

any other suggestions? what u think of astaro?
 
Old 11-20-2006, 11:00 AM   #6
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
Quote:
Originally Posted by eNtoS
what i need is virus scanning...

any other suggestions? what u think of astaro?
ipcop (suggested by acid_kewpie) and astaro both seem like two good options for you to test... there's also other, of course - but this is a good start IMHO...

Last edited by win32sux; 11-20-2006 at 11:02 AM.
 
Old 11-20-2006, 12:15 PM   #7
eNtoS
Member
 
Registered: Feb 2006
Distribution: slackware, ubuntu, knoppix, backtrack, debian
Posts: 35

Original Poster
Rep: Reputation: 15
I checked out IPcop, but it doesnt have (builtin) antivirus scanning...

any suggestions regarding antivirus scanning of all traffic passing through the machine?
 
Old 11-20-2006, 01:18 PM   #8
Tortanick
Member
 
Registered: Jul 2006
Distribution: Debian Testing
Posts: 299

Rep: Reputation: 30
You need the Copfilter extension, that adds real time virus scanning and spam filtering (either or both depending on how you set it up). http://copfilter.org/ However I never got much luck making copfilter working so I can't help you here, maby someone else can.

I can also recomend getting the URLfilter extension and advanced proxy from http://www.urlfilter.net/ and http://www.advproxy.net/
Advproxy just makes Urlfilter work better (allegedly)

Use URLfilter to block adverts and dangerous websites, the easiest way would be to stop useing the copfilter blacklists (default) and start useing http://urlblacklist.com/ (read http://urlblacklist.com/?sec=download for a list of whats in each catagory)

To switch URLfilter over just use the option in the built in GUI. urlblacklist is NOT free but it is on the honour system so no password is needed.

Last edited by Tortanick; 11-20-2006 at 01:21 PM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
AntiVirus software for linux jason2 Linux - Software 4 06-16-2010 05:29 PM
Antivirus software for linux linuxqa Linux - Security 5 09-12-2005 09:24 PM
Does anybody use antivirus software in Linux? yzrider210 Linux - General 50 12-04-2004 09:30 PM
Antivirus Software For Linux treedstang Linux - Software 7 04-30-2004 03:22 PM
Antivirus software for linux ??????? jmax24 Linux - Software 4 04-19-2004 01:42 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:42 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration