LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 02-17-2009, 04:50 AM   #1
cuckoo
LQ Newbie
 
Registered: Feb 2009
Posts: 1

Rep: Reputation: 0
Setting up a server - separate hardware firewall? Help appreciated...


Hello all,

I'd really appreciate your help with this dilemma...

I am setting up a dedicated web server for a fairly major online business. I have looked at my options and due to budget constraints I think I will have to choose between:

1) A server from a good company (such as Dedipower) with good support but no separate hardware firewall. I think I can get this for around £80 ($120) per month.
2) A server from a cheaper company (probably 1and1) with external hardware firewall. This would be around £80 ($120) per month including the firewall and lots of other freebies such as SSL certificates. I have heard bad things about 1and1 but their offers are hard to resist...

I guess my questions are really:
a) How important for security is an external hardware firewall? The web server would be a Bastille server with carefully configured iptables anyway.
b) Can anyone think of a good compromise? Are there any companies that offer good support and also hardware firewall, for around £80-90 ($120) per month.

Thanks for your help.
 
Old 02-19-2009, 03:45 PM   #2
tokico
Member
 
Registered: Jan 2009
Posts: 49

Rep: Reputation: 18
iptables is secure and stable. Don't think you need an hardware firewall. If you configure iptables really carefully, then you will not have any problems.

Go for the 1and1 option.
 
Old 02-19-2009, 04:36 PM   #3
adam999
Member
 
Registered: Sep 2006
Posts: 105

Rep: Reputation: 18
If your talking about off site dedicated hosted servers? then you wont need to bother with firewall etc, that will be taken care of for you by the hosting company
 
Old 02-19-2009, 05:29 PM   #4
chort
Senior Member
 
Registered: Jul 2003
Location: Silicon Valley, USA
Distribution: OpenBSD 4.6, OS X 10.6.2, CentOS 4 & 5
Posts: 3,660

Rep: Reputation: 76
Quote:
Originally Posted by adam999 View Post
If your talking about off site dedicated hosted servers? then you wont need to bother with firewall etc, that will be taken care of for you by the hosting company
Depends what you mean by that. Every hosting company is going to have some kind of firewall between the wild Internet and your instance, but you won't necessarily be able to submit change requests for it. Usually the provider's firewall is wide-open to your IP by default, so it's not necessarily doing much good unless you have the ability to submit requests for the rules that are deployed.

That being said, if you really know how to configure a firewall properly (hint: most people who think they know how actually don't), then there really isn't much benefit to having a hardware firewall too.

Maybe if the firewall was a beefy enterprise-grade box it would offer some extras beyond what Netfilter can do (due to in-hardware handling of packets vs. strictly software), but what you're likely to get as a dedicated firewall is a branch-office type box.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Setting up firewall / nat server da644 Linux - Networking 1 08-02-2005 08:22 PM
Setting up firewall and internal vpn server alon005 Linux - Security 3 12-27-2004 02:16 AM
setting up a linux server + firewall + nat ddaas Linux - Security 7 10-14-2004 06:42 PM
A few hardware issues, help appreciated TheRepublican Linux - Hardware 1 02-23-2004 08:34 AM
Setting firewall script & server pautorras Linux - Networking 1 09-09-2003 02:19 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 08:11 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration