LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-01-2001, 01:38 AM   #1
Wynd
Member
 
Registered: Jul 2001
Distribution: Slackware 12
Posts: 511

Rep: Reputation: 32
What's a good firewall?


I read in a book that Linux is so secure it doesn't need a firewall, but i don't believe it, so what would you recommend as a firewall? (unless of course the above is true...)
 
Old 08-01-2001, 02:45 AM   #2
mcleodnine
Senior Member
 
Registered: May 2001
Location: Left Coast - Canada
Distribution: s l a c k w a r e
Posts: 2,731

Rep: Reputation: 45
'linux' is not a good firewall. Most distributions have a LOT of stuff running that really shouldn't be _public_.

'linux' that has been tamed with ipchains/iptables _can_ be a very good logging firewall.

'linux' that is set up as a proxy service can be a very effective firewall and performance tool.

It's up to the admin to make it so.
 
Old 08-01-2001, 03:14 AM   #3
cinnix
Member
 
Registered: Jun 2001
Location: Northern Ohio
Distribution: RedHat, Engarde and LFS
Posts: 237

Rep: Reputation: 30
I would be scared to read a book that made such a foolish remark.
 
Old 08-01-2001, 04:20 AM   #4
raz
Member
 
Registered: Apr 2001
Location: London
Posts: 408

Rep: Reputation: 31
Wynd,

It depends on how much money you have to spend and how critical the network/server data is.

Linux is not secure as default, you can switch of all the public services, but you may as well just unplug it from any network connection.
I would start by burning the book your reading.

He's a list that shows you the type of systems you can use.

A Linux firewall:
need: PC + software
cost: cheap
Security rating out of 100 if configured correctly: 60

A Cisco ACL router with firewall SW:
Need: a Catalyst router with FWSW
cost: £2000 up
Security rating out of 100 if configured correctly: 40

A Cisco PIX firewall
Need: a PIX box
Cost: £2000 up
Security rating out of 100 if configured correctly: 80

A Solaris box with Checkpoint + 10 VPN connections
Need: a x86 or Sun System
Cost: £6000 up to £180,000 "depends on Sun's hardware"
Security rating out of 100 if configured correctly: 70

A Nokia box running Checkpoint FW1 + 10 VPN
Need: a Nokia FW1 box
Cost: £30,000 up
Security rating out of 100 if configured correctly: 90

A Watchguard firebox system:
Need: a lovely red looking box
Cost: £2000 up to £50,000
Security rating out of 100 if configured correctly: 90

There are plenty of others, I've just listed the main ones so you get an idea.
Linux is fine for stopping most attacks, but not so fine for critical or sensitive data systems.

/Raz
 
Old 08-01-2001, 11:41 AM   #5
mcleodnine
Senior Member
 
Registered: May 2001
Location: Left Coast - Canada
Distribution: s l a c k w a r e
Posts: 2,731

Rep: Reputation: 45
SuSE has a commercial firewall product that runs with no HDD. It's a 'live' ISO image on a cd-rom that you configure with a floppy. Once configuration is complete you make the floppy disko read-only a-la the little read-only tab. It prices out at $US695 or around there.

Oh. And you need a box and 2 NICs as well.
 
Old 08-01-2001, 12:51 PM   #6
Wynd
Member
 
Registered: Jul 2001
Distribution: Slackware 12
Posts: 511

Original Poster
Rep: Reputation: 32
Don't worry, i didn't buy the book

I just wanted a firewall program for personal use, no expensive hardware stuff
 
Old 08-06-2001, 11:59 AM   #7
r3b00t
Member
 
Registered: May 2001
Distribution: OpenBSD 3.0-beta
Posts: 50

Rep: Reputation: 15
A firewall is as secure (good) as the rules you feed it...
 
Old 08-07-2001, 01:06 AM   #8
zhenwu
Member
 
Registered: Jul 2001
Location: Taiwan (ex-Victoria BC)
Distribution: RH 9.0
Posts: 126

Rep: Reputation: 15
If it's just a personal firewall, check out pmfirewall for linux.

www.pointman.org

Once you install it, it has a very cool configurator that asks you a bunch of questions, then sets the ipchains rules from your answers.

Of course, you need to have ipchains up and running...
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
whats a good firewall daedalusonlinux Linux - Software 4 11-22-2005 11:15 AM
IPTABLES Firewall (Good enough????) wardialer Linux - Security 10 03-01-2005 09:29 AM
Is this a good firewall? Mega Man X Linux - Networking 9 09-04-2004 03:15 AM
Good Firewall roiboy Linux - Security 5 05-31-2004 08:40 PM
A good firewall? UnknownDarkness Linux - Software 1 02-12-2003 12:54 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:55 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration