Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here. |
Notices |
Welcome to LinuxQuestions.org, a friendly and active Linux Community.
You are currently viewing LQ as a guest. By joining our community you will have the ability to post topics, receive our newsletter, use the advanced search, subscribe to threads and access many other special features. Registration is quick, simple and absolutely free. Join our community today!
Note that registered members see fewer ads, and ContentLink is completely disabled once you log in.
Are you new to LinuxQuestions.org? Visit the following links:
Site Howto |
Site FAQ |
Sitemap |
Register Now
If you have any problems with the registration process or your account login, please contact us. If you need to reset your password, click here.
Having a problem logging in? Please visit this page to clear all LQ-related cookies.
Get a virtual cloud desktop with the Linux distro that you want in less than five minutes with Shells! With over 10 pre-installed distros to choose from, the worry-free installation life is here! Whether you are a digital nomad or just looking for flexibility, Shells can put your Linux machine on the device that you want to use.
Exclusive for LQ members, get up to 45% off per month. Click here for more info.
|
 |
04-22-2006, 02:58 PM
|
#1
|
Member
Registered: Aug 2005
Location: California
Distribution: CentOS 5
Posts: 54
Rep:
|
routers as a security measure
As mentioned in my other posts, I run a stand-alone FC-5 box. It's located in the DMZ area on a spur of a large network.
I'm thinking of obtaining a small router/firewall of some kind and adding it as a security measure. I would assign it my static IP, and have it forward requests bound for ports 80, 22, and 25 to the server. (Those are the only 3 that I want open to the outside world.)
Question. Do you see any advantages or disadvantages to a scheme like that? One advantage I see is that by adding a hardware firewall, it would make absolutely sure only those ports were open. Any drawbacks?
|
|
|
04-22-2006, 03:57 PM
|
#2
|
Senior Member
Registered: Jan 2003
Location: Devon, UK
Distribution: Debian Etc/kernel 2.6.18-4K7
Posts: 2,380
Rep:
|
It's kind of double insurance and does work. I have a firewall on my adsl/modem router and a separate more sophisticated one on the server. The router firewall does a very good job and I can then fine tune exclusions such a s abusive ip addresses on the server firewall.
|
|
|
04-24-2006, 02:57 AM
|
#3
|
Member
Registered: Aug 2005
Location: California
Distribution: CentOS 5
Posts: 54
Original Poster
Rep:
|
re: routers as a security measure
Which model do you recommend for me and how much can I expect to pay? Remember, all I need is a basic firewall device that will prevent banned IP's from reaching the box. There will be only one machine (the server) attached.
Preferably something with an easy-to-use terminal program that will let me type in those addresses via remote access.
|
|
|
04-24-2006, 05:39 AM
|
#4
|
Member
Registered: Sep 2005
Location: Old Blighty
Distribution: Slackware, NetBSD
Posts: 536
Rep:
|
Quote:
Which model do you recommend for me and how much can I expect to pay?
|
One solution would be an old laptop with a couple of pcmcia nics. This would give you a full-blown Linux system (much more flexible than the firmware in a router), a built-in UPS etc. A 486 would suffice, the only snag would be getting sufficient ram (4mb would be tight (but usable with some tweaking), 8mb would be doable, 12mb should be very comfortable, any more than 16mb would probably be overkill for a small dedicated firewall). Should be cheaper than a hardware router too.
|
|
|
04-24-2006, 12:20 PM
|
#5
|
Senior Member
Registered: Jan 2003
Location: Devon, UK
Distribution: Debian Etc/kernel 2.6.18-4K7
Posts: 2,380
Rep:
|
Following on ioerror there is a Linux based version available called coyotelinux that would do this very well on 486 + boxes.
|
|
|
All times are GMT -5. The time now is 02:00 AM.
|
LinuxQuestions.org is looking for people interested in writing
Editorials, Articles, Reviews, and more. If you'd like to contribute
content, let us know.
|
Latest Threads
LQ News
|
|