| ||||||
| 5/17 |
| 2001/4/18 [Computer/Networking] UID:21019 Activity:very high |
4/19 Anyone know good firewall info ideally balancing maximum security with
minimum effort (ignoring cost and competence)?
\_ If you want a ready-made solution, you can pick up a sonicwall
for about $1000--they are fairly decent. For high security, I
would recommend OpenBSD with ipf--syntax is well documented and
straightforward. http://www.openbsd.org and for the ipf page,
(also known as ipfilter), http://coombs.anu.edu.au/ipfilter
Mail me if you want some tips. -John
\_ yeah. sure. is this a consulting job?
\_ yes, its called an 'airwall'. Complete internet security
accomplished with about 30 seconds worth of effort. Simply find
your router and unplug its internet connection. Where do I send
my consulting invoice?
\_ OpenBSD -> 30 min to 1 hr install, 30 min setup, 30 min testing.
firewall?
\_ and 4ever to make world. Linux + iptables is fine
\_ Yeah if you don't care about
BTW, D0 U KN0W WH1CH V3R510N 0F G11BC 1 N33D 2 RUN
K3RN31 2.4? I C4N7 F1ND TH3 R1GHT RPM on RH.C0M.
performance, security, stability
logging and working stateful
filtering.
RUNN1G K3RN31 2.4? I C4N7 F1ND TH3 R1GHT 1Z on RH.C0M.
BTW, What's the IP Addr of your
firewall? I could use an extra
machine for running setiathome.
\_ D00D U R 50 R1GH7! M4K3 W0R1D SUX! Y WOU1D U BU11D
UR B1N4R135 4ND 11BR4R145 WH3N U C4N U53 RPM5?!?
BTW, D0 U KN0W WH1CH V3R510N 0F G11BC 4ND LD 1 N33D 4
RUNN1G K3RN31 2.4? I C4N7 F1ND TH3 R1GHT 1Z 0N RH.C0M.
\_ So how come Mac and Windows users don't get shit for
not compiling every program they use and relying on
things like Install Shield or .sit and worrying whether
their registry settings get all f'ed up?
\_ D00D U U53 M$ LO53*?!? U N33D 2 UPGR4D3 2 4 R341
05! 1 C4N 1N57411 31337 R3D H47 GN00/L1NSUX 4 U!
N0 1 U535 M4C5. 17 15 4 S10W A55 T0Y 4 L17713
K1D5! 31337 H4X0R5 411 U53 DU41 C3L3 733'5 0C'3D
2 1 G1G! |
| 5/17 |
|
| www.openbsd.org Our efforts emphasize portability, standardization, correctness, 45 proactive security and 46 integrated cryptography. OpenBSD supports binary emulation of most programs from SVR4 (Solaris), FreeBSD, Linux, BSD/OS, SunOS and HP-UX. OpenBSD is freely available from our FTP sites, and also available in an inexpensive 3-CD set. The project funds development and releases by selling 49 CDs and 50 T-shirts, as well as receiving donations. Mirrors, by country: 54 AT 55 AU 56 BE 57 BE 58 BR 59 BR 60 BR 61 CA 62 CA 63 CA 64 CH 65 CZ 66 DE 67 DE 68 DE 69 DE 70 DK 71 GR 72 HU 73 ID 74 ID 75 IE 76 IT 77 IT 78 JP 79 MY 80 NO 81 PL 82 PL 83 PT 84 PT 85 SI 86 TR 87 TW 88 UA 89 UK 90 US 91 US 92 US 93 YU This site Copyright 1996-2004 OpenBSD. |
| coombs.anu.edu.au/ipfilter -> coombs.anu.edu.au/ipfilter/ Donations Thanks to those who have been able to support IP Filter through 13 donations of hardware. The current implementation provides a small set of tools, which can easily be used and integrated with regular unix shells and tools. Amongst these tools is a new addition, ipftest, which is provided so that you can test a rule set before committing it to use in your kernel. It can also be used to flush the current firewall rule set or delete individual firewall rules. This allows for testing of firewall rule list and examination of how a packet is passed along through it. Documentation on ioctl's and the format of data saved to the logging character device is provided so that you may develop your own applications to work with or in place of any of the above. |