Gentoo Archives: gentoo-user

From: James <wireless@×××××××××××.com>
To: gentoo-user@l.g.o
Subject: [gentoo-user] Re: Foss hardened router?
Date: Thu, 09 Jun 2016 18:39:07
Message-Id: loom.20160609T202957-588@post.gmane.org
In Reply to: Re: [gentoo-user] Foss hardened router? by Corbin Bird
1 Corbin Bird <corbinbird <at> charter.net> writes:
2
3 >
4
5 > >> Ideally, there would be a gentoo-based hardened router for sale
6
7 > Take a spare desktop system, strip / rebuild / reconfigure it as a
8 > single purpose system.
9 > Lots of card slots and memory are very good to have for this system.
10 > It works, but can be a pain space and time wise. ( Firewall / DHCP
11 > Server / Router ).
12 > I have done this twice for relatives.
13
14 Hmmmm. I was thinking the full hardened protocol::
15 grsecurity::
16
17 https://wiki.gentoo.org/wiki/Hardened/Grsecurity2_Quickstart
18 (there is acutally quite todo on this effort).
19
20 ssp, vpn-encryption engine, etc etc.
21
22
23
24 > http://www.ipcop.org/
25
26 Although security conscience, I see no evidence/detail as to how
27 this firewall ipcop distro is hardened; that why ideally, I'd like
28 it to be based on gentoo. Furthermore, infrequent releases does
29 not suggest they are on top of all security isses, ymmv. The closest I've
30 found is (2) workstations offerings by blueness:: tin-hat and lilblue.
31
32 And those are not tuned to be 'routers' but could be, with
33 hardened expertise at the keyboard. As you add codes to a hardened
34 system, things can become challenging..... hence the desire for
35 a gentoo-hardened-router vendor, or guide.
36
37
38 James