Berkeley CSUA MOTD:Entry 20606
Berkeley CSUA MOTD
 
WIKI | FAQ | Tech FAQ
http://csua.com/feed/
2025/05/25 [General] UID:1000 Activity:popular
5/25    

2001/2/15-16 [Computer/Networking] UID:20606 Activity:high
2/15    I manage the network of a small company.  10 workstations, 10 PCs.
        They are hooked to the internet via a DSL line.  We're thinking of
        putting in a firewall. Is there a DSL modem with built-in firewall?
        Or am I better off using an el-cheapo PC as firewall? Recommendations?
        Thanks.
        \_ run free/openbsd; use ipf.  nat with ipnat, redirect: ipmasqadm.
           if you run nameservice for internal and external, you want to
           have the external one chrooted, and point the /etc/resolv.conf
           to the internal nameserver (this file is outside the chrooted dir).
           make sure you get the securest copy of bind - there was a recent
           exploit. if you chose linux, you might want to consider using
           iptables with real nat and real state.  with freebsd, you can use
           mpd-netgraph should you later want a vpn. with linux, you can use
           poptop.  Running the nameserver in a chrooted section in linux is a
           little bit more effort but doable. - paolo ps, point the internal
           one to some trusted nameserver.
           \_ If you are worried about dns, check out djbdns. It is much
              better and much more secure than bind.
              I would recommend running OpenBSD over FreeBSD. OpenBSD is
              much better audited, and has more frequent fixes for security
              holes. Also in a locked down firewall setup (turn of httpd,
              inetd, etc) there have been no remote exploits in 3 years.
              Other options include NetBSD. You can get it to boot and
              run on almost anything. If you are worried about the form
              factor (noise, etc) get a IPX or a Qube2 with NetBSD. Its
              pretty secure and fast.
              \_ ipx's are kind of noisy. at least the one i have is.
                 \_ are you using the stock Hawk drive? If so that
                    is your problem. Replace with a Quantum Fireball,
                    and noise goes down by 75%.
        \_ Highly recommend FreeBSD running ipf/ipnat (if you have to
           NAT)  Config syntax is pretty straightforward once you start
           looking at it, and is well documented.  It's very fast, and
           it will be good on a P166.  A colleague is a great fan of
           running it on the sort of embedded, fanless PCs that
           advantech (<DEAD>www.advantech.com<DEAD> make.  Mail me if you
           want some help.  -John
        \_ if you're not into optimizing and configuring things and
           running external services like www, there is a linksys
           dsl modem/hub product that has a webserver configuration
           interface, and address translation, so you can set that
           up and then plug a hub into that and connect your office.
           or spend a couple of hours bringing up a unix box
           with two interfaces and turn on ip masqeraduing and dhcp to
           connect your office.
        \_ by your description, it sounds like you already have a dsl modem,
           and just need a firewall/hub box.  There are plenty on the market.
           just look around.
           \_ in other words, you have no recommendations.  fuck off
        \_ Cisco PIX. It is the standard firewall.
           \_ Is Cisco PIX any better than a typical OpenBSD/ifp setup?
              \_ Oh yeah. The PIX is pretty damn secure. It has a custom
                 OS (not IOS) that has many layers of security and it is
                 completely audited. Every patch/upgrade is hand checked
                 and then a horribly complex set of attacks are executed
                 agaist it. PIX defends banks, enterprises, governments
                 in thier most secure locations. If someone tells you
                 they can get past a PIX, its probably because they
                 paided someone to unplug it from the network.
        \_ MegaPath DSL had me buy a Netopia R3100 (IDSL) which seems to
           have pretty decent NAT/Firewalling/PPTP functionality (I don't
           actually use any of it, but it's there...)  --dbushong
2025/05/25 [General] UID:1000 Activity:popular
5/25    

You may also be interested in these entries...
2008/8/5-10 [Computer/Networking] UID:50788 Activity:nil
8/5     It looks like my company has started blocking HTTPS tunneling.
        I used to do this by tunneling SSH through the HTTP/HTTPS proxy
        server, but this seems to have stopped working. Does anyone know
        how the implementation of tunneling detection works, and whether
        there are widely available implementations? We run a bunch of MS
        stuff, so I imagine we're running an MS proxy server or something.
	...
2007/8/9-13 [Computer/Networking] UID:47570 Activity:low
8/9     Is there an automated way to change the IP of an XP machine? I have
        tests that need to get run on two separate sub-nets that now require
        me to physically go in and change the IP address of the test box.
        Cygwin is also installed if that helps any. Thanks
        \_ There are a few sort of hackey ways to do it:
           1) automate the mouse clicks and key strokes witto do it:
	...
2007/6/28-7/2 [Computer/Networking] UID:47104 Activity:nil
6/28    what?
        We are deeply, deeply sorry to say that due to licensing constraints,
        we can no longer allow access to Pandora for most listeners located
        outside of the U.S. We will continue to work diligently to realize
        the vision of a truly global Pandora, but for the time being we are
        required to restrict its use. We are very sad to have to do this, but
	...
2007/6/28-7/2 [Computer/SW/SpamAssassin] UID:47111 Activity:nil
6/28    Q: What are folks using these days for anti-spam measures?  I'm
        looking for something that integrates with my MTA (postfix) or my
        delivery agent (sieve).  Currently I'm using a crufty version of
        spamassassin wired into postfix via amavisd-new.  It's decent, but I
        don't want to be bothered with manually upgrading spamassassin or
        updating rulesets on a regular basis.  Anyone have any experience
	...
2006/10/31-11/2 [Computer/SW/OS/Windows] UID:45057 Activity:moderate
10/31   A friend of mine said he's loving Microsoft again because Bill G
        is starting to donate all of his money to charity. He's boycotting
        Google, Yahoo, and other mega companies because they're too big and
        too power and thinks they're all becoming the old Microsoft, whereas
        Microsoft has recently done a lot of good things like investing in
        education and charity. He just paid for a copy of Microsoft Windows
	...
2006/5/23-28 [Computer/Networking] UID:43157 Activity:nil
5/23    I have DSL through AT&T. The service was originally established
        through PacBell, transitioned to SBC, and now AT&T. I still have
        my original plan and never converted to a SBC Yahoo! (now AT&T
        Yahoo!) account. I noticed the price will be a lot cheaper if I
        do. Are there any drawbacks? I thought someone mentioned some
        negatives about the Yahoo! tie-in once upon a time.
	...
2006/5/8 [Computer/SW/Security] UID:42976 Activity:moderate
5/8     why you are getting all that blue frog spam
        http://q.queso.com/archives/001917 - danh
        \_ While I'm not ready to call it outright bullshit, I'm skeptical:
           * Most DNS operators with a clue set TTL values to cache records
             for 24 hours to one week.  The DNS notify mechanism leaves much
             to be desired.  Thus, changing a DNS pointer is unlikely to
	...
2006/2/18-23 [Computer/Networking] UID:41923 Activity:low
2/18    My DSL modem's ip address is 192.168.0.1, my internal network
        behind my router is 10.0.0.x. Is there a way I can configure
        the router so I can access the DSL modem from my 10.0.0.x
        network directly without re-wiring? Static routes? I tried it
        but no much luck. I also tried changing my internal network to
        192.168.0.x, but still does not work. Thanks.
	...
2006/1/28-31 [Computer/Networking] UID:41585 Activity:low
1/28    Just switched to Comcast from SBC and generally happy with it.  But
        can someone please explain to me why they are constantly pumping
        ARP traffic through the network?  It seems harmless, but I'm curious
        as I didn't see it with DSL.  It's a little disconcerting to see
        constant traffic on your router, even if ARPs are harmless from
        a bandwidth perspective, and it makes the WAN send/receive light
	...
2006/1/22-24 [Computer/Networking] UID:41477 Activity:nil
1/21    I am trying to setup a small network for my girlfriend's
        mom's company.  They just bought an accounting package
        which requires windows 2003 server.  And they want internet
        access from each computer.  How should the network be setuped?
        Would it be dumb to use static IP for each computer and a
        computer as internet gateway?
	...
2005/8/29-30 [Computer/Networking] UID:39329 Activity:moderate 54%like:37400
8/29    What's the difference between a hub, a switch and a router?  Thx.
        \_ AFAIK, probably be corrected by someone:
           hub: Allows communication on a LAN with bandwith shared amongs all
                the nodes on the hub and maxing out at the max line speed.
           switch: Allows communication on a LAN with bandwith greater than
                the max line speed (point to point)
	...