1 |
Hello, |
2 |
|
3 |
I've decided to take the plunge and build my first, full featured |
4 |
firewall on Gentoo. At first I was going to use 'gnap' but further |
5 |
reading reveals that this sort of derived firewall is stateless, |
6 |
and I want a statefull firewall. It's also masked. |
7 |
(feel free to correct me if I miss something). |
8 |
|
9 |
The firewall will have (3) nics, Outside(static IP) |
10 |
DMZ for several web servers, mail server and DNS secondaries |
11 |
and a private for a DNS server, PCs(doz) and assorted Linux systems. |
12 |
So after googling for a while, I could not find any detailed documentation |
13 |
on building a gentoo based robust firewall (I sure thought I'd ran across |
14 |
such a page/document, but, nothing today). |
15 |
|
16 |
I did find some packages to 'ease the pain' on configuring iptables |
17 |
and completing the firewall: Recommendations here? |
18 |
fwbuilder |
19 |
bastille |
20 |
kmyfirewall |
21 |
firestarter |
22 |
|
23 |
I did find this gentoo document: |
24 |
http://www.gentoo.org/doc/en/home-router-howto.xml |
25 |
This example is for a 2 nic basic firewall. |
26 |
I need a dmz that will have web servers, dns servers, and |
27 |
will ensure security. |
28 |
|
29 |
I did find one Debian-centric security document: |
30 |
http://www.debian.org/doc/manuals/securing-debian-howto |
31 |
|
32 |
Alternatively, since this machine is only going to be a firewall |
33 |
& ethernet router so rather than securing a complete Gentoo system |
34 |
I could just use a 'firewall cd' installation, if one exists |
35 |
as a Gentoo derivative. |
36 |
|
37 |
Any other ideas or recommendations on documents or firewall install |
38 |
config on gentoo or a gentoo derivative are most welcome? |
39 |
|
40 |
Note: my firewall experience is mostly with openbsd. |
41 |
|
42 |
|
43 |
James |
44 |
|
45 |
-- |
46 |
gentoo-user@g.o mailing list |