Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here. |
Notices |
Welcome to LinuxQuestions.org, a friendly and active Linux Community.
You are currently viewing LQ as a guest. By joining our community you will have the ability to post topics, receive our newsletter, use the advanced search, subscribe to threads and access many other special features. Registration is quick, simple and absolutely free. Join our community today!
Note that registered members see fewer ads, and ContentLink is completely disabled once you log in.
Are you new to LinuxQuestions.org? Visit the following links:
Site Howto |
Site FAQ |
Sitemap |
Register Now
If you have any problems with the registration process or your account login, please contact us. If you need to reset your password, click here.
Having a problem logging in? Please visit this page to clear all LQ-related cookies.
Get a virtual cloud desktop with the Linux distro that you want in less than five minutes with Shells! With over 10 pre-installed distros to choose from, the worry-free installation life is here! Whether you are a digital nomad or just looking for flexibility, Shells can put your Linux machine on the device that you want to use.
Exclusive for LQ members, get up to 45% off per month. Click here for more info.
|
 |
05-09-2006, 04:51 PM
|
#1
|
LQ Newbie
Registered: May 2006
Location: Stockholm
Posts: 4
Rep:
|
Switch or router? Need the firewall?
I want to replace my old 10 Mbit hub with something faster. Either with a switch or with a router. If a choose a switch I get more ports for the money but no built in firewall.
I have a home network with a couple of Windows boxes and a Debian box. Each Windows computer has a software firewall installed, which seems to work nicely. I have done nothing to improve the security for my Debian installation.
My ISP is generous with IPs.
To keep it simple and cheap, and to get some extra ports, I would like to choose a switch. But is it worth to go for a router with built in firewall? Do I really need it for my Debian? If so, would it be as good to have a sw firewall (setting up IP tables?).
Help me with answering in noobish, please 
|
|
|
05-09-2006, 05:48 PM
|
#2
|
LQ Newbie
Registered: Nov 2005
Posts: 12
Rep: 
|
In my humble opinion, it is always wise to run a software firewall on a computer that has a network or internet connection, regardless of its operating system.
Firestarter is a quick and easy GUI to set up iptables. I highly suggest installing it.
If your ISP provides multiple net-accessible IPs and you have no need for a NAT router, just get a gigabit switch.
|
|
|
05-09-2006, 06:38 PM
|
#3
|
Member
Registered: Aug 2004
Location: Arizona
Distribution: Linux Mint
Posts: 81
Rep:
|
If this is for home usage, wouldn't a router/switch/AP combo from maybe Linksys or D-Link fit your needs? Unless you're doing this in a business of some sort, I don't know what having a seperate device for a router and a switch would accomplish for you. Even the cheap combo routers would be faster and more efficient than what you're using now.
|
|
|
05-10-2006, 03:41 AM
|
#4
|
LQ Newbie
Registered: May 2006
Location: Stockholm
Posts: 4
Original Poster
Rep:
|
Thanks for your opinions guys!
Quote:
Originally Posted by Amuro-Ray2020
...I don't know what having a seperate device for a router and a switch would accomplish for you.
|
I was not thinking of having both a switch and a router, just one of them. My ISP throws as many IPs at me as I want so IPs wouldn't be a reason for me to get router. I was more thinking of the built in firewall that most routers offer. Can I live without it when it comes to my Debian box? Would it be as good to buy the cheaper switch and just install a software firewall?
|
|
|
05-10-2006, 04:14 AM
|
#5
|
Senior Member
Registered: May 2004
Location: Australia
Distribution: Gentoo
Posts: 3,545
Rep:
|
If you've got a few boxes lying around, set one up as a gateway and run a firewall on that. That's what I have here, works a treat. ISP -> gateway/firewall -> switch -> LAN 
|
|
|
05-10-2006, 07:03 AM
|
#6
|
LQ Newbie
Registered: Mar 2006
Location: Atlanta,Georgia USA
Distribution: Mandriva 2010
Posts: 15
Rep:
|
switch or router?
I have an identical setup:small office LAN with two XPs and a Debian based distro. My connection is EarthLink dsl. The gateway is a zoomx5 modem/router with configurable firewall. Linksys and others have similar products. They are only in the $80-$90 range, easy to set up and worth every penny when you consider the miserable alternatives. I also have a firewall on the Linux laptop which you might have to configure or the router may be denied access but if you have the right firewall you won't need advanced programming skills.I am still a newbie myself compared to these Linux warriors and I don't have the time to fix an infected machine. The more popular Linux becomes the more it will become the target of the darkside so unless you like to live dangerously use a firewalled router and configure it carefully.
|
|
|
05-10-2006, 12:02 PM
|
#7
|
Member
Registered: Apr 2006
Location: Cape Town, South Africa
Distribution: Gentoo 2006.1(2.6.17-gentoo-r7)
Posts: 222
Rep:
|
If I was you I would make use of IPtables for a network firewall...
You can also make it host based with IPkungfu if you cant figure it out.
|
|
|
05-10-2006, 02:11 PM
|
#8
|
Senior Member
Registered: May 2004
Location: Albuquerque, NM USA
Distribution: Debian-Lenny/Sid 32/64 Desktop: Generic AMD64-EVGA 680i Laptop: Generic Intel SIS-AC97
Posts: 4,250
Rep:
|
My suggestion Get a router and use the software firewalls on each machine as backup. Set up the router, NAT firewall with whatever open ports you need, then control the open ports on each individual maching with the software firewall.
I am assuming you're not looking for extreme security here, only REASONABLE security. Firewall interfaces, like Kerio or ZoneAlarm on Windows, and Firestarter or Guarddog on Linux are very easy to manage, and quite serviceable.
Messing around directly with iptables is a sure prescription for insanity unless it's something you really need to do.
|
|
|
All times are GMT -5. The time now is 04:58 AM.
|
LinuxQuestions.org is looking for people interested in writing
Editorials, Articles, Reviews, and more. If you'd like to contribute
content, let us know.
|
Latest Threads
LQ News
|
|