Announcement

Collapse
No announcement yet.

linux firewall software ?

Collapse
This topic is closed.
X
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    linux firewall software ?

    Hi, I am planning to use a old computer as a firewall, is there software that supports:

    * Firewall (both directions)
    *UPnP for dynamically configured port forwarding
    * Web Antivirus
    * Web Antispam
    * E-Mail Antivirus
    * Transparent HTTP-Proxy
    * Hotspot/Wireless Security
    * SIP VoIP Support
    * Network Address Translation
    * Multi IP address (aliases)
    * HTTPS web interface
    * Connection statistics
    * Log of networking traffic
    * DHCP-Server
    * NTP-Server
    * Intrusion Detection System
    * automatic update of anti-virus definitions.
    *easy and intuitive configuration

    Interfaces:
    Interface A is connected to a ADSL modem
    interface B is connected to a switch running high-power 802.11 A/B/G (with a external antenna) and cabled lan

    I am planning to use a old computer as a firewall, the computer routes traffic between the interfaces.

    #2
    Re: linux firewall software ?

    How old of a computer? Give the name and model number, the CPU config, amount of RAM, the names of the NICs and the wireless chip, etc?

    To all of your questions the answer is a conditional yes, conditioned on your hardware being SO OLD that it is not practical to use any more. IF you are planning on using an SX486 with 512MB of RAM and a 300MHz 16 bit CPU then .... NO.
    "A nation that is afraid to let its people judge the truth and falsehood in an open market is a nation that is afraid of its people.”
    – John F. Kennedy, February 26, 1962.

    Comment


      #3
      Re: linux firewall software ?

      Originally posted by GreyGeek
      How old of a computer? Give the name and model number, the CPU config, amount of RAM, the names of the NICs and the wireless chip, etc?

      To all of your questions the answer is a conditional yes, conditioned on your hardware being SO OLD that it is not practical to use any more. IF you are planning on using an SX486 with 512MB of RAM and a 300MHz 16 bit CPU then .... NO.
      Pentium III processor, 256 Megabytes of RAM, 1 GB of Hard Disk Space
      vid:
      ATI Xpert 98, chipset: ATI 3D Rage Pro Turbo

      lan cards:
      2x RealTek 8129/8139 chipset SMC EZ Card 10/100 1211TX 10BaseT

      wlan access point
      http://www.radiolabs.com/products/wi...cess-point.php with external antenna
      or optional( with a MiniPCI-to-PCI adapter card ):
      http://www.demarctech.com/products/r...-pci-card.html
      or
      EnGenius EMP-8603 28dB Atheros 11a/b/g mini-PCI
      EMP-8603 Premium is mini-PCI types A module, supports dual-band (2.4GHz & 5GHz) high transmit output power up to 400mW in 5GHz and 800mW in 2.4GHz. It has 2x mmcx connectors and 2x jumper wires for external DC 5 volt or 9 ~ 24 V
      power supply. It uses Atheros 6th generation AR5414 chipset.
      data on : http://www.engeniustech.com/resource...t_20081204.pdf

      Comment


        #4
        Re: linux firewall software ?

        Originally posted by isprins
        .....
        Pentium III processor, 256 Megabytes of RAM, 1 GB of Hard Disk Space
        OK, IF you use a distro designed for small and/or old machines. Best one, IMO: Puppy

        vid:
        ATI Xpert 98, chipset: ATI 3D Rage Pro Turbo
        Uh oh... OLD ATI video card. The latest ATI drivers won't run the old Rage cards. The old ATI drivers won't recognize the new kernels, the new kernels won't work with the old ATI drivers. Catch 22. IF you need a Graphical desktop you'll have to stick with VESA, otherwise you will need to become familiar with mc or nano or pico or vim and command line operation of your box. My favorite console editor is mc (midnight commander). It is like Dolphin and Kate combined, but for the console.

        lan cards:
        2x RealTek 8129/8139 chipset SMC EZ Card 10/100 1211TX 10BaseT
        Should be no problem. http://www.linux.org/docs/ldp/howto/...t-HOWTO-4.html

        wlan access point
        http://www.radiolabs.com/products/wi...cess-point.php with external antenna
        or optional( with a MiniPCI-to-PCI adapter card ):
        http://www.demarctech.com/products/r...-pci-card.html
        or
        EnGenius EMP-8603 28dB Atheros 11a/b/g mini-PCI
        EMP-8603 Premium is mini-PCI types A module, supports dual-band (2.4GHz & 5GHz) high transmit output power up to 400mW in 5GHz and 800mW in 2.4GHz. It has 2x mmcx connectors and 2x jumper wires for external DC 5 volt or 9 ~ 24 V
        power supply. It uses Atheros 6th generation AR5414 chipset.
        data on : http://www.engeniustech.com/resource...t_20081204.pdf
        Shouldn't be a problem.

        A good Linux admin reference (written 10 years ago, a few years after your box was made) is rute. I mention it because it features administering Linux from the command line and covers doing what you want to do with the kind of equipment you are using.
        "A nation that is afraid to let its people judge the truth and falsehood in an open market is a nation that is afraid of its people.”
        – John F. Kennedy, February 26, 1962.

        Comment


          #5
          Re: linux firewall software ?

          Originally posted by GreyGeek
          A good Linux admin reference (written 10 years ago, a few years after your box was made) is rute. I mention it because it features administering Linux from the command line and covers doing what you want to do with the kind of equipment you are using.
          This is an absolute GEM to have. If this were a M$ reference book, one, it wouldn't be available 'free' as it is here, and two, it would cost you an arm and a leg!
          Using Kubuntu Linux since March 23, 2007
          "It is a capital mistake to theorize before one has data." - Sherlock Holmes

          Comment


            #6
            Re: linux firewall software ?

            I noticed an errata for RUTE, which is something I hadn't seen before. Here it is:

            1st edition

            FIRST PRINTING ERRATA LIST Home

            Command and programming corrections:

            Page 100: 2/5 from the top of the page, add the following paragraph before "The above causes the message...":
            The MTA may require that addresses be enclosed in < > braces. If you get errors, try instead MAIL FROM:<me@my.machi.ne> and RCPT TO:<them@their.machi.ne>. (This is one of the places where you really do type in the < and >.)

            Page 305: 2/5 from the top of the page, add the following between "...internal mail server." and "local_delivery: This transport...":
            Instead of using hosts_override and hosts as explained above, these options can be deleted and the lookuphost router changed to:

            lookuphost:
            driver = domainlist
            route_list = "* 192.168.2.1 byname"
            transport = remote_smtp

            This says that all recipient addresses matching the domain * must be forwarded to the SMTP host of IP address 192.168.2.1. This alternative preserves the behavior, except that no unnecessary lookups are done that are just going to be overridden by the hosts_override option.

            Typographical and grammatical corrections:

            # Page 38: 1/4 from the bottom, should be, "nnn[G] Go to line nnn of the file." That is, without the dash.

            # Page 58: 1/4 from the top, delete "cooledit" from the sentence "cooledit The best editor for...".

            # Page 90: 1/3 from the top, should read, "These states are modified by a trailing < for a process with negative nice value,"

            # Page 174: 1/3 from the bottom, "...the additional notation $(command) is equivalent to `command` except that..." That is, the quotes about command are backquotes. There are some incorrect fonts on this page, but the meaning should still be clear.

            # Page 300: In the center, "It then performs a DNS MX query (or MX lookup) for the domain toonland.net."

            # Page 340: At the top, "...to use a simple, non-error correcting protocol..."

            # Page 341: 3/5 from the bottom, "This approach works because mgetty and..."

            # Page 342: Near the bottom, "...if someone wants to send a fax, while another person has dialed the Internet."

            # Page 422: In the center, delete the line, "Migrating from..." which is a duplicate of the header.

            # Page 438: At the top, "Keep this window open throughout the entire setup..."

            # Page 463: Near the bottom, "...there were about 400 modules, totalling about 9 megabytes."

            # Page 521: In the center of the page, "Removing fingerprints: Your system identifies itself to" should be changed to "Removing fingerprints: See Nonstandard messages above." (Yeah, I know what you are thinking: "Is there supposed to be a whole paragraph here?" Actually there isn't - its just a duplicate LaTeX item.)

            # Page 561: Near the top, "Most vendors try to comply with this standard, and..."

            # Page 622: Left column, 1/3 from the bottom, "Symmetric Multiprocessor Support, see SMP"
            "A nation that is afraid to let its people judge the truth and falsehood in an open market is a nation that is afraid of its people.”
            – John F. Kennedy, February 26, 1962.

            Comment


              #7
              Re: linux firewall software ?

              Thanks!
              Using Kubuntu Linux since March 23, 2007
              "It is a capital mistake to theorize before one has data." - Sherlock Holmes

              Comment


                #8
                Re: linux firewall software ?

                I've added the ERRATA sheet to the PREFACE page. If anyone wants it, I'm attaching it here. Just copy it (as root) into /usr/share/doc/kde/HTML/en/rutebook as node2.html (overwriting the existing file).

                Attached Files
                Using Kubuntu Linux since March 23, 2007
                "It is a capital mistake to theorize before one has data." - Sherlock Holmes

                Comment


                  #9
                  Re: linux firewall software ?

                  Back OT

                  Code:
                  apt-cache search firewall
                  iptables is the tool for everything, but you need to know it. Fireflier, mason, kmyfirewall, arno-iptables-firewall, guidedog... Dunno, there is plenty. Install and see what you like.
                  Once your problem is solved please mark the topic of the first post as SOLVED so others know and can benefit from your experience! / FAQ

                  Comment

                  Working...
                  X