1 |
Corbin Bird <corbinbird <at> charter.net> writes: |
2 |
|
3 |
> |
4 |
|
5 |
> >> Ideally, there would be a gentoo-based hardened router for sale |
6 |
|
7 |
> Take a spare desktop system, strip / rebuild / reconfigure it as a |
8 |
> single purpose system. |
9 |
> Lots of card slots and memory are very good to have for this system. |
10 |
> It works, but can be a pain space and time wise. ( Firewall / DHCP |
11 |
> Server / Router ). |
12 |
> I have done this twice for relatives. |
13 |
|
14 |
Hmmmm. I was thinking the full hardened protocol:: |
15 |
grsecurity:: |
16 |
|
17 |
https://wiki.gentoo.org/wiki/Hardened/Grsecurity2_Quickstart |
18 |
(there is acutally quite todo on this effort). |
19 |
|
20 |
ssp, vpn-encryption engine, etc etc. |
21 |
|
22 |
|
23 |
|
24 |
> http://www.ipcop.org/ |
25 |
|
26 |
Although security conscience, I see no evidence/detail as to how |
27 |
this firewall ipcop distro is hardened; that why ideally, I'd like |
28 |
it to be based on gentoo. Furthermore, infrequent releases does |
29 |
not suggest they are on top of all security isses, ymmv. The closest I've |
30 |
found is (2) workstations offerings by blueness:: tin-hat and lilblue. |
31 |
|
32 |
And those are not tuned to be 'routers' but could be, with |
33 |
hardened expertise at the keyboard. As you add codes to a hardened |
34 |
system, things can become challenging..... hence the desire for |
35 |
a gentoo-hardened-router vendor, or guide. |
36 |
|
37 |
|
38 |
James |