Linux - SecurityThis forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.
Notices
Welcome to LinuxQuestions.org, a friendly and active Linux Community.
You are currently viewing LQ as a guest. By joining our community you will have the ability to post topics, receive our newsletter, use the advanced search, subscribe to threads and access many other special features. Registration is quick, simple and absolutely free. Join our community today!
Note that registered members see fewer ads, and ContentLink is completely disabled once you log in.
If you have any problems with the registration process or your account login, please contact us. If you need to reset your password, click here.
Having a problem logging in? Please visit this page to clear all LQ-related cookies.
Get a virtual cloud desktop with the Linux distro that you want in less than five minutes with Shells! With over 10 pre-installed distros to choose from, the worry-free installation life is here! Whether you are a digital nomad or just looking for flexibility, Shells can put your Linux machine on the device that you want to use.
Exclusive for LQ members, get up to 45% off per month. Click here for more info.
Distribution: Mandrake 9.2 and a couple of RH7.3 Apache servers
Posts: 153
Rep:
Hardware or software firewall?
On my small home network I use a cablemodem and an SMC cable router with a built in firewall/print server and 4 port switch. I was thinking about using one of my old boxes to set up a Linux based firewall, Freesco to be nore precise because I heard that it is easy to set up and I dont know much about firewalls. My question is weather there is an advantage or disadvantage for that matter to using the Linux firewall over the one built into my router. Also, does the processor speed of the firewall box have any affect on your internet access speed? Like if I stick a p133 between my P4-1.4 and the outside world will it slow me down?
It really depends on how paranoid you are. An extra layer of security never hurts. I would not recommend relying totally on a single layer. I decided not to put my wireless Linksys in the front simply because performance degraded every time that I got port scanned. The amount performance degradation would obviously depend on the hardware that you use. Using old ISA NICs in the firewall could hurt in some situations.
Distribution: Mandrake 9.2 and a couple of RH7.3 Apache servers
Posts: 153
Original Poster
Rep:
I would say that I'm pretty damn paranoid. Would it hurt to put a Linux firewall between my cable router/firewall and my cable modem, and on the same token would my internet access speed suffer by havin to pass through 2 firewalls? As for nics I would be using a pair of Linksys PCI cards in either a p133/48meg or a p233/24meg.
I am running pretty much the exact configuration. I am running Linux on a p133/ and Cable Modem and had no problems with overloading the process, even with multiple internal hosts on the same internet connection.
I did disable filtering at the router (If you do, lock down configuration options from the external port) and it made no difference.
Good luck
I use a Linux box running iptables for my firewall. My decision between hardware and software firewall was cost. [at the time] I could either spend $300 on a hardware router or bring an old P60 back to life for free. Possibly in the long run, I will spend more on electricity, but I am happy with the Linux firewall now and I will not switch. The Linux firewall is more configurable (not as easy at times) and keeps very good logs (depends on the setup). The P60 w/32MB has no problem with keeping up with my connection, ADSL 1.4Mb down and 256K up, the machine is always idle. The box is completely stripped, just a MB, floppy, tape, one 800M HD and 2 NICs.
Hi,
I think it depends on how secure your network should be. A Linux firewall is very cheap (I use a P100, 800MB HD, 32MB RAM) but you have always to pay attention to some security holes concerning kernel, iptables etc. Most of the time a hardware firewall use a very secure operating system and you need not any updates (but I don't know your firewall).
LinuxQuestions.org is looking for people interested in writing
Editorials, Articles, Reviews, and more. If you'd like to contribute
content, let us know.