LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-05-2003, 06:48 PM   #1
kragbax
LQ Newbie
 
Registered: Jun 2003
Location: MN
Distribution: Fedora Core 2
Posts: 18

Rep: Reputation: 0
Help me find a firewall


I need a free or sub $50 linux based firewall that has the following features.

Needs:
Firewall
Routing (2 networks + internet)
Packet shaping (per user or IP)
File Server (samba, listen to internal NIC only)
Web configuration
Easy to to use installer or has very good directions that are easy to follow.

Would be nice but not required:
Content filter
Antispam
Intrusion detection

Mandrake MNF seemed to fit several of these criteria but I found that it kept complaining about missing files (shouldn't it install everything?!?) and a web configuration that would work for about 2 minutes before it loses the connection.
 
Old 11-06-2003, 01:46 AM   #2
idaho
Member
 
Registered: Aug 2003
Location: Portland, Oregon
Distribution: RedHat, Libranet
Posts: 438

Rep: Reputation: 30
One of the advantages of linux over MSWindows is that you can run many services off of a single box. A good place to break that rule is for firewalls.

I recommend that you look for a cheap dual NIC system to use as a dedicated firewall (look at http://lrp.steinkuehler.net/ for links to good canned Linux based dedicated firewall solutions) and get a second cheap box to run your Samba server, mail server, and proxy server.
 
Old 11-06-2003, 06:33 AM   #3
aqoliveira
Member
 
Registered: Dec 2001
Location: Portugal
Distribution: /Red Hat/Fedora/Solaris
Posts: 622

Rep: Reputation: 30
Howzit

I see that u currently running RH) which can do mostly everthing u mentioned:

1.FW = IPtables/Netfilter
2.Routing, also possible in doing NAT = Ptables/Netfilter
3. goto www.freshmeat.net for an application that dows it there r a few
4. Samba also available
5. Apache web server also available

Content filter can use censornet, squidguard, Dans Gaurdian in conjunction with squid Proxy server which is a default app with RH9. Will also find a antispam module which can work with Postfix and sendmail default app with RH9. IDS there are a few wich can be downloaded from www.freshmeat.net but the one I used was Snort.

To be honest with u it will be difficult to find a distro that has all ure needs like one size fits all but the nice thing about linux is that u r not bound to one distro it? all portable from one to the other. I mentioned RH because u currently use it but this doesn't bind u to use only the apps that come with it there r other FW, Web servers etc.

Must agree with idaho would not stick so may services on one machine especially on a FW, rather get a cheap box and run FW seperatly from other machines running other services needed.

Hope this helps

chow
 
Old 11-06-2003, 11:05 AM   #4
cyph3r7
Member
 
Registered: Apr 2003
Location: Silicon Valley East, Northern Virginia
Distribution: FreeBSD,Debian, RH, ok well most of em...
Posts: 238

Rep: Reputation: 30
yeah I wouldn't reccomend all those services on the same box but hey who am I to complain I do it on my firewall at home for simplicity. So here is what I had done on RedHat that matches your requirements:

1 - Iptables to firewall and as a GUI I use fwbuilder, also used for packet shaping
2 - Samba for File Server (have it on ano box but it can be done on same)
3 - webmin, a nice web based config util
4 - apt-get as an installer over rpm

5 - Squid and Dan's Guardian for caching and content filtering
6 - Black lists for anti-spam with spamassasin
7 - IDS I use snort

I had this setup for a long time. I finally switched over to FreeBSD as the OS for a little less bloat and more speed but basically the same apps.

Good luck
 
Old 11-06-2003, 04:18 PM   #5
markus1982
Senior Member
 
Registered: Aug 2002
Location: Stuttgart (Germany)
Distribution: Debian/GNU Linux
Posts: 1,467

Rep: Reputation: 46
Remember today you have not only to have a firewall, since it is only possible to do some packet filtering with it. You have to protect the services at the application level.

A firewall with an insecure ftp-server configuration or for instance a firewall with a wu-ftpd server will NEVER be considered as secure... do not rely on bloated standard configurations, write your OWN configuration and check man pages, etc for more information.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Where I can find firewall logs? Vie Linux - Software 3 02-07-2006 12:15 AM
can't find modules for firewall script strimp099 Linux - Networking 1 10-05-2004 10:26 PM
Help me find a Linux Firewall please. :) 2Gunz Linux - Security 7 10-27-2003 02:07 AM
How to find a firewall project example? bobowd Linux - Security 4 07-08-2002 04:49 AM
Postfix runs until reboot and can't find firewall joshuamorin Linux - Newbie 0 01-11-2002 06:53 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 02:09 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration