| |||||||
| Register | FAQ | Members List | Calendar | Arcade | Search | Today's Posts | Mark Forums Read |
![]() |
| | LinkBack | Thread Tools | Rate Thread |
| ||||
| Most of the Linux firewall "packages" are based around the same code. Typically this is IPChains as a firewall, Squid as a proxy, BIND as a caching DNS server and so on. This makes most of the packages around the same level of power. Better packages will be using Netfilter rather than IPChains. Netfilter is a stateful firewall, in that it keeps track of connections rather than just acting as a basic filter. Another alternative is something like GTA's GNATBox Lite, which you can find at http://www.gnatbox.com/Pages/gblight.html - it's a single floppy firewall with GTA's GNAT Box software, but with restrictions to make it unattractive to business users. Basically, the limited version only allows 5 IPs to communicate from behind the network, and 4connections in from outside. AidanII
__________________ |
| ||||
| well Adian, i installed mandrake 8.2 and my rigs behind the proxy seem to be browsing really slow. does windows do a better job in sharing internet connection? i haven't configured IPChains yet cause i had all kinds of problems with it and the internet connection thingy on my prior install. about BIND, do i really need it i'm ready to scrap mandrake and install SNF (single network firewall 7). btw, does SNF need a host OS? i read the README.TXT and it can be installed on 95/98/ME, but will not install on xp. does antone have any info on SNF? anything?
__________________ Shuttle SB61G2 | PIV 2.8C @ 3.5GHz |
| ||||
| Quote:
Not sure why your rigs behind the firewall are so slow, unless running the proxy is too heavy a task for the fw machine to cope with. If that's the case, run it without proxying. From what I've seen Linux does a pretty good job of sharing a internet connection - I've seen it happily fill 4Mbit of a 4Mbit line. IPChains is the core firewall (a packet filter). Without that configured (or netfilter), you do not have any firewall capabilities beyond network address translation. BIND is only needed if you want to proxy DNS queries. Generally, it's not too much of a problem if you don't. SNF7.2 uses a Mandrake linux install tailored to this application, so it comes with it's own host OS. I've yet to see a firewall doesn't require a host OS, be it Linux, Solaris, NT, IPSO or PIX. SNF7.2 again looks like IPChains and a proxy. The advantage of one of the prepackaged setups is that you don't have to spend so long working out what needs to be installed and what doesn't. This excludes all the tuning up you'd need to do to a standard OS to bring it up to the firewall level. AidanII
__________________ |
![]() |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
| Rate This Thread | |
| |
Similar Threads | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Ned Kelly's Last Stand. | mookydooky | Random Nonsense! | 2 | 15th November, 2004 02:44 PM |
| What does AOA stand for? | danrok | Random Nonsense! | 3 | 23rd April, 2004 07:57 PM |
| Where does the 8RDA+ stand w/ 3500 RAM? | SYNeR | EPoX MotherBoards | 34 | 15th December, 2002 05:51 PM |
| Short Political Quiz, where do you stand? | dimmreaper | Random Nonsense! | 48 | 5th November, 2002 03:16 PM |
| Are you a stand up guy? | Allan | Random Nonsense! | 11 | 29th November, 2001 12:21 AM |