Re: Linux firewall vs Windows and Hardware based firewalls

From: Kjetil Kjernsmo (kjetil_at_kjernsmo.net)
Date: 07/31/03

  • Next message: Timothy Webster: "Best? groupware"
    To: debian-user@lists.debian.org
    Date: Thu, 31 Jul 2003 12:02:06 +0200
    
    

    On Thursday 31 July 2003 08:11, Andre Volmensky wrote:
    > What are the advantages of a linux firewall over something like
    > Windows with WinRoute on it, or even a hardware based firewall. What
    > are the disadvantages etc. I know I am asking on a linux users
    > mailing list, but I would also like reply's not to be too bias.

    I have no experience with neither Windows routers or hardware routers,
    but I have a great router running Linux from a floppy.

    It's an old box I was given, and it has a 133 MHz Pentium CPU. That's
    certainly overkill for my purpose, but that is what I got.... It would
    probably be appropriate for your purpose. I ripped the harddrive out,
    it boots from a floppy.

    The floppy is from the Coyote Linux project: http://www.coyotelinux.com/
    but you could try floppyfw too http://www.zelow.no/floppyfw/
    I couldn't get it to work with my DSL provider, which is strange since
    I'm using the same provider as the author.

    Anyway, I figured it will be so extremely seldom I have to change
    anything in there, I disabled any access method beyond going to the box
    and pop the floppy out. No telnetd, no sshd. I figured, if there is
    some vulnerability in the firewall code, it is not even going to be a
    daemon listening on the inside, ready to give the attacker a shell.
    Also, the RAMDisk isn't big, and when there is no harddrive, even if the
    attacker gets into the firewall box, it's a complete wasteland when it
    comes to tools.

    Now, do _that_ on windows! :-)

    Cheers,

    Kjetil

    -- 
    Kjetil Kjernsmo
    Astrophysicist/IT Consultant/Skeptic/Ski-orienteer/Orienteer/Mountaineer
    kjetil@kjernsmo.net  webmaster@skepsis.no  editor@learn-orienteering.org
    Homepage: http://www.kjetil.kjernsmo.net/        OpenPGP KeyID: 6A6A0BBC
    -- 
    To UNSUBSCRIBE, email to debian-user-request@lists.debian.org 
    with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
    

  • Next message: Timothy Webster: "Best? groupware"

    Relevant Pages