Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here. |
Notices |
Welcome to LinuxQuestions.org, a friendly and active Linux Community.
You are currently viewing LQ as a guest. By joining our community you will have the ability to post topics, receive our newsletter, use the advanced search, subscribe to threads and access many other special features. Registration is quick, simple and absolutely free. Join our community today!
Note that registered members see fewer ads, and ContentLink is completely disabled once you log in.
Are you new to LinuxQuestions.org? Visit the following links:
Site Howto |
Site FAQ |
Sitemap |
Register Now
If you have any problems with the registration process or your account login, please contact us. If you need to reset your password, click here.
Having a problem logging in? Please visit this page to clear all LQ-related cookies.
Get a virtual cloud desktop with the Linux distro that you want in less than five minutes with Shells! With over 10 pre-installed distros to choose from, the worry-free installation life is here! Whether you are a digital nomad or just looking for flexibility, Shells can put your Linux machine on the device that you want to use.
Exclusive for LQ members, get up to 45% off per month. Click here for more info.
|
 |
12-23-2005, 01:21 PM
|
#1
|
LQ Newbie
Registered: Apr 2005
Location: FL
Distribution: FC4
Posts: 20
Rep:
|
Firewall...?
Merry christmas to all...
I just picked up an old box from a client. Its got an AMD-K6 MMX, so guessing its gonna be about 233Mhz. It has a 4 Gb hard drive in it also.
I know its plenty good for a firewall program, so my question is WHAT firewall program and which version of linux should I run it on?
What are the suggestions from the forum?
thx in advance,
ziggy
|
|
|
12-23-2005, 04:02 PM
|
#2
|
LQ Guru
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870
|
well, the linux kernel (v2.4/v2.6) standard firewall is netfilter... the tool to configure it is iptables... you will have these pretty much regardless of which distro you choose... most "firewall programs" you see are just front-ends for iptables...
http://netfilter.org/
http://iptables-tutorial.frozentux.n...-tutorial.html
so basically what i'm trying to say is that as long as you have at least kernel 2.4 you can use any decent distro on that box in order to have a cool firewall...
some iptables front-ends you might like:
http://www.shorewall.net/
http://www.simonzone.com/software/guarddog/
http://www.fs-security.com/
but if you're comfortable working from the command-line your best bet is to forget the front-ends and just write your own iptables script...
PS: merry christmas to you also...
Last edited by win32sux; 12-23-2005 at 04:06 PM.
|
|
|
12-23-2005, 04:20 PM
|
#3
|
LQ Newbie
Registered: Apr 2005
Location: FL
Distribution: FC4
Posts: 20
Original Poster
Rep:
|
thx alot dude! That gives me some "Holiday Reading" to do.
ziggy
|
|
|
12-23-2005, 05:17 PM
|
#4
|
Member
Registered: Mar 2004
Location: Watching it snow in bush Alaska
Distribution: *ubuntu, Smoothwall, WinXP Pro
Posts: 126
Rep:
|
One other thing you could do with an old, slow comp is to make it a stand alone firewall. There are a couple of distros that do this - Smoothwall and IPCop to name just two. They would run just fine on that hardware.
Currently I'm running Smoothwall on a P3 700 mhz which is really overkill but it was the only old comp I could get for free. So a K6 should do fine.
www.smoothwall.org
www.ipcop.org
|
|
|
12-23-2005, 09:56 PM
|
#5
|
Senior Member
Registered: Feb 2003
Location: Calif, USA
Distribution: PCLINUXOS
Posts: 2,918
Rep: 
|
I have run both Smoothwall and IPCop at various times on my Pentium 100, 32MB RAM, 1GB hard drive (upgraded from 512MB).
They have worked great for my small home network. I added a wireless router/access point a few months ago.
If you are talking stand alone firewall either is worth checking out.
|
|
|
12-24-2005, 06:39 AM
|
#6
|
Senior Member
Registered: Jun 2004
Location: Australia
Distribution: Mandriva/Slack - KDE
Posts: 1,672
Rep:
|
Smoothwall here on a P166/32... Easy firewall.
|
|
|
12-24-2005, 06:54 PM
|
#7
|
LQ Guru
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870
|
there's also Devil Linux: http://www.devil-linux.org/ MWAHAHAHAHA!!!
i've also read great things about clarkconnect (though i've never used it): http://www.clarkconnect.com/
there' like tons of gnu/linux distros made specially for gateway servers... but if all you need is a firewall then any generic distro will be fine... slackware, debian, fedora, you name it...
PS: there's also some non-Linux (BSD) options which seem interesting, such as: http://www.m0n0.ch/wall/
Last edited by win32sux; 12-24-2005 at 06:55 PM.
|
|
|
12-24-2005, 07:45 PM
|
#8
|
LQ Newbie
Registered: Apr 2005
Location: FL
Distribution: FC4
Posts: 20
Original Poster
Rep:
|
Well I have taken alaskazimm's advice and went with smoothwall... So far I like it. As said in this post, it looks easy. And I see it has many other options bundled into it. More specifically excited about Snort.
thx again. I'll post if i get stuck.
|
|
|
12-26-2005, 11:16 AM
|
#9
|
Member
Registered: Mar 2004
Location: Watching it snow in bush Alaska
Distribution: *ubuntu, Smoothwall, WinXP Pro
Posts: 126
Rep:
|
Glad to help!
Smoothwall also has support forums that are worth checking out if you haven't already.
|
|
|
12-26-2005, 12:00 PM
|
#10
|
LQ Newbie
Registered: Apr 2005
Location: FL
Distribution: FC4
Posts: 20
Original Poster
Rep:
|
Will do! I'm guessing that the configuration part of the firewall is based on iptables rules. Does anyone know of a good tutorial? I'm using an old one, just because it was the most basic for me to jump into, now that I have HOW the rules are written, I want to learn some of the more advanced reasons why you would want rule X in chain Y.
Thanks again,
ziggy
|
|
|
All times are GMT -5. The time now is 08:23 PM.
|
LinuxQuestions.org is looking for people interested in writing
Editorials, Articles, Reviews, and more. If you'd like to contribute
content, let us know.
|
Latest Threads
LQ News
|
|