Re: [SLE] a good firewall?

From: Darryl Gregorash (raven_at_accesscomm.ca)
Date: 02/06/05

  • Next message: Carl E. Hartung: "Re: [SLE] Re: 9.2 scsi install: no fstab found"
    Date: Sun, 06 Feb 2005 15:21:10 -0600
    To: suse-linux-e@suse.com
    
    

    Henry Tang wrote:

    > Our company's sonicwall just died out and i need a firewall
    > replacement. Sonicwall is really strange.. The sonicwall has two
    > ports wan and lan.. The wan is hooked up to the csu/dsu router and the
    > lan is hooked up to a hub for internal networks. The sonicwall is only
    > used to block ports but all computers in the lan, sonicwall, and
    > csu/dsu router uses static ip provided by our internet provider. It is
    > really a weird setup which i don't approve of, but I need something
    > that can do the job like sonicwall. I dunno if it is possible.. I have
    > a firewall at home but the lan is a internal ips 192.xxx

    If all you need is something to block a few ports, then stick with what
    you already know. Iptables and its cousin iproute2 together can provide
    a fully stateful firewall, plus fully classful traffic shaping, but you
    need to invest the time to learn them. A decent software tool to assist
    the design process also helps (and SuSEfirewall2 is *not* a decent tool
    in a corporate environment). Shorewall is another good tool, in addition
    to the ones already mentioned by others. It's advantage is that it's all
    under the GPL.

    Based on your description above, iptables is really overkill. However,
    it can replace everything you have mentioned, and do a heck of a lot
    more besides (most of which you don't seem to need right now, but it's
    there in the future if you ever do need it) Personally, I think it is
    definitely worth the effort to learn iptables and iproute2 now, and try
    to convince the powers-that-be to replace all that stuff with a Linux
    box. But if you don't think you have much chance to convince them, stick
    with what you know.

    I really wouldn't complain too much about static IPs all over the place;
    using them saves you from having to do anything more complicated than
    some simple routing, and maybe a bit of port forwarding :-)

    -- 
    Check the headers for your unsubscription address
    For additional commands send e-mail to suse-linux-e-help@suse.com
    Also check the archives at http://lists.suse.com
    Please read the FAQs: suse-linux-e-faq@suse.com
    

  • Next message: Carl E. Hartung: "Re: [SLE] Re: 9.2 scsi install: no fstab found"

    Relevant Pages

    • Re: iptables configuration
      ... >> that if a 'virus/trojan' initiated a connection to the net, the firewall ... >> would not protect the LAN. ... The LAN is NATed with private IPs to one public IP. ... the ports that are used by services running on linux. ...
      (comp.os.linux.security)
    • Re: Sonicwall hangs/freezes within minutes.
      ... No DHCP on router or Sonicwall. ... > site to site VPN and access to Sonicwall by GlobalVPN. ... > through LAN or VPN interfaces. ... T. Sean Weintz - T. Sean Weintz - T. Sean Weintz - T. Sean Weintz May be copied freely without the express permission of T. Sean Weintz. ...
      (comp.security.firewalls)
    • alg.exe
      ... ich habe ein kleines LAN mit Router, ... Ports habe ich mir leider nicht notiert (meine aber, vierstellig, evtl. ... Gegenstelle war natürlich eine WAN-Adresse (also ... 'Application Layer Gateway Service' und womit muß ich jetzt rechnen? ...
      (microsoft.public.de.security.netzwerk.sicherheit)
    • alg.exe
      ... ich habe ein kleines LAN mit Router, ... Ports habe ich mir leider nicht notiert (meine aber, vierstellig, evtl. ... Gegenstelle war natürlich eine WAN-Adresse (also ... 'Application Layer Gateway Service' und womit muß ich jetzt rechnen? ...
      (microsoft.public.de.security.heimanwender)
    • Re: Exchange problems After changing FireWall Harware
      ... For a MS discussion of the ports needed for SBS and RWW, ... using any device on your LAN as a web server. ... DNS and DHCP on the server. ... I can't send mails to Internet by OWA ...
      (microsoft.public.windows.server.sbs)