LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-22-2003, 03:08 AM   #1
vivck
LQ Newbie
 
Registered: Oct 2003
Posts: 2

Rep: Reputation: 0
Question Firewall


Could anyone tell me the difference between a Hardware firewall and a Software firewall. Also which could be the best solution to protect my system. I have my website running on RedHat Linux 9.
 
Old 10-22-2003, 10:10 AM   #2
KB1IKN
LQ Newbie
 
Registered: Oct 2003
Distribution: Debian \ Gentoo
Posts: 11

Rep: Reputation: 0
The main difference is price. You'll pay more for a dedicated firewall rather than a little piece of software. I'm toying around with IPChains. You can setup a dedicated fw with a linux box and 2 nics

--Matt
 
Old 10-22-2003, 12:58 PM   #3
markus1982
Senior Member
 
Registered: Aug 2002
Location: Stuttgart (Germany)
Distribution: Debian/GNU Linux
Posts: 1,467

Rep: Reputation: 46
Well you do also pay mostly for the GUI development. Like there are firewalls out there which are based on netfilter and just add a GUI and managing tool for Winblows to it ... if I'm not mistaken the WatchGuard series is such a kind of firewall.
 
Old 10-24-2003, 12:53 PM   #4
banderson
Member
 
Registered: Oct 2003
Location: Salt Lake City, UT
Distribution: RedHat 9
Posts: 35

Rep: Reputation: 15
Use iptables if you are on version 2.4 of the kernel or higher. iptables will do stateful inspection of the packets.
 
Old 10-25-2003, 02:46 PM   #5
chort
Senior Member
 
Registered: Jul 2003
Location: Silicon Valley, USA
Distribution: OpenBSD 4.6, OS X 10.6.2, CentOS 4 & 5
Posts: 3,660

Rep: Reputation: 76
Well what are traditionally called "hardware" firewalls are more properly labeled "firmware" firewalls. They generally have very few moving parts and the firewall code itself is loaded from some type of NVRAM. "Software" firewalls can mean anything from specialized software running on dedicated hardware, to just an extra program you install on a normal system. Usually "software" firewall means an extra program you add. The middle ground would cover both "appliances", which are very close to the same as a firmware firewall, but actually have hard disk drives and run fairly standard hardware, to a "bastion host" which is just a dedicated host running a particular set of software for firewalling and maybe proxying.

You can create either a software firewall or a bastion host on Linux, depending on your resources. A firmware firewall would cost a significant amount of money (such as a Cisco Secure PIX, Netscreen, etc...) and an appliance would also cost, although generally not as much (some companies for instance make IPCop appliances that sell for several hundred dollars).

I did leave one possibility out: You could buy a consumer (or "SoHo") firmware firewall, such as Linksys, D-Link, Netgear, Belkin, etc... Those would cost between $80 and $150, depending on the model and any special promotions. The difference is those units are not very configurable, they almost never have a true DMZ, and they're usually very limited in the amount of IPs they can support.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
BSD Firewall vs Linux Firewall ? rootlinux Linux - Security 5 08-29-2007 07:38 AM
Firewall lets ips which are not in the firewall ... why ? sys7em Linux - Networking 2 06-30-2005 12:50 PM
Firewall with features of a Sidewinder firewall? abcampa Linux - Security 4 04-22-2005 04:24 PM
slackware's /etc/rc.d/rc.firewall equivalent ||| firewall script startup win32sux Debian 1 03-06-2004 09:15 PM
Firewall Builder sample firewall policy file ? (.xml) nuwanguy Linux - Networking 0 09-13-2003 12:32 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:47 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration