1 |
Or use monmotha and be up an running in a couple of minutes. I am using |
2 |
3 nics at the moment with it. I did try shorewall, but the setup time |
3 |
and learning curve was so much greater I dumped it (the complexity |
4 |
worried me as well - complex means it may be vulnerable to |
5 |
misconfiguration). Mind you, on complex/commercial setups it probably |
6 |
has an advantage, but not for SOHO/home use. |
7 |
|
8 |
BillK |
9 |
|
10 |
|
11 |
On Sat, 2005-08-27 at 12:23 +0200, Oscar wrote: |
12 |
> I've used both firehol and shorewall, and they're both great! |
13 |
> But for a more advanced setup, I would recommend shorewall (firehol is a bit tricky at some points, like port-forwarding), it will save you a lot of time (setting up a 3 NIC firewall with shorewall takes less than 30 minutes)... |
14 |
> |
15 |
> Oscar |
16 |
> |
17 |
> On Fri, 26 Aug 2005 22:36:39 +0000 (UTC) |
18 |
> James <wireless@×××××××××××.com> wrote: |
19 |
> |
20 |
> > Hello, |
21 |
> > |
22 |
> > I've decided to take the plunge and build my first, full featured |
23 |
> > firewall on Gentoo. At first I was going to use 'gnap' but further |
24 |
> > reading reveals that this sort of derived firewall is stateless, |
25 |
> > and I want a statefull firewall. It's also masked. |
26 |
> > (feel free to correct me if I miss something). |
27 |
> > |
28 |
> > The firewall will have (3) nics, Outside(static IP) |
29 |
> > DMZ for several web servers, mail server and DNS secondaries |
30 |
> > and a private for a DNS server, PCs(doz) and assorted Linux systems. |
31 |
> > So after googling for a while, I could not find any detailed documentation |
32 |
> > on building a gentoo based robust firewall (I sure thought I'd ran across |
33 |
> > such a page/document, but, nothing today). |
34 |
> > |
35 |
> > I did find some packages to 'ease the pain' on configuring iptables |
36 |
> > and completing the firewall: Recommendations here? |
37 |
> > fwbuilder |
38 |
> > bastille |
39 |
> > kmyfirewall |
40 |
> > firestarter |
41 |
> > |
42 |
> > I did find this gentoo document: |
43 |
> > http://www.gentoo.org/doc/en/home-router-howto.xml |
44 |
> > This example is for a 2 nic basic firewall. |
45 |
> > I need a dmz that will have web servers, dns servers, and |
46 |
> > will ensure security. |
47 |
> > |
48 |
> > I did find one Debian-centric security document: |
49 |
> > http://www.debian.org/doc/manuals/securing-debian-howto |
50 |
> > |
51 |
> > Alternatively, since this machine is only going to be a firewall |
52 |
> > & ethernet router so rather than securing a complete Gentoo system |
53 |
> > I could just use a 'firewall cd' installation, if one exists |
54 |
> > as a Gentoo derivative. |
55 |
> > |
56 |
> > Any other ideas or recommendations on documents or firewall install |
57 |
> > config on gentoo or a gentoo derivative are most welcome? |
58 |
> > |
59 |
> > Note: my firewall experience is mostly with openbsd. |
60 |
> > |
61 |
> > |
62 |
> > James |
63 |
> > |
64 |
> > -- |
65 |
> > gentoo-user@g.o mailing list |
66 |
> > |
67 |
-- |
68 |
William Kenworthy <billk@×××××××××.au> |
69 |
Home! |
70 |
|
71 |
-- |
72 |
gentoo-user@g.o mailing list |