new firewall!

Old Dec 23, 2008 | 10:05 PM
  #1  
not12listen's Avatar
Thread Starter
Registered User
 
Joined: Jun 2007
Posts: 786
From: sf bay area, ca
Car Info: 06 WRX Wagon
new firewall!

so, i've been using a 3Com wireless router (with stateful packet inspection enabled) for quite some time. i've had no issues with it, but, being the fact that i'm a bit of a nerd, i finally got off my butt and dedicated a machine to build a IPCop Linux firewall.

honestly, the feature set is pretty impressive.
1. vpn server
2. segregated LAN/WLAN/DMZ networks
3. available integrated AntiVirus
4. integrated DynDNS support
5. available integrated spam filtering

and quite a few other options.

i'm curious if anyone else has done something similar or not. if yes, what have your results been?

for those interested at looking into this:
http://ipcop.org/
Old Dec 23, 2008 | 10:13 PM
  #2  
mcowger's Avatar
Registered User
iTrader: (8)
 
Joined: Dec 2004
Posts: 1,737
From: Seattle
Car Info: 2009 A3 2.0T quattro
My results is that I dont like paying for a 100W+ PSU to be running for my firewall, and just run OpenWRT on a Linksys box

I get the vpn server, segregated networks, dyndns for less than 5W, and let my email provider deal with the AV/Spam filtering.
Old Dec 24, 2008 | 05:58 AM
  #3  
evsoul's Avatar
VIP Member
iTrader: (1)
 
Joined: Jul 2004
Posts: 5,588
From: Santa Rosa
Car Info: 2005 Unicorn
I don't see how running a dedicated "system" as a firewall is worth the power usage to protect a few computers... especially to protect computers that PROBABLY aren't under watch/attack.

But for a very long time I ran an OpenBSD firewall computer. I would recommend it over ANY distro of linux... OpenBSD = the MOST secure OS on earth. if you're gonna do it... do it right
Old Dec 24, 2008 | 09:28 AM
  #4  
Lboogie's Avatar
banned
iTrader: (5)
 
Joined: Jan 2008
Posts: 1,456
From: NorCal, SF East Bay
Car Info: 2007 WRX Limited | vf43'D
That's a lotta security, for home? Must have a ton of kiddie **** to protect!

i kid, i kiddie kid.
Old Dec 24, 2008 | 10:30 AM
  #5  
rau's Avatar
rau
Something Custom
iTrader: (9)
 
Joined: Aug 2003
Posts: 14,505
From: Las Vegas NV
Car Info: 2018 Grand Cherokee Limited Ecodiesel EOC Stage 1
Originally Posted by Lboogie
That's a lotta security, for home? Must have a ton of kiddie **** to protect!

i kid, i kiddie kid.
Old Dec 25, 2008 | 12:00 AM
  #6  
not12listen's Avatar
Thread Starter
Registered User
 
Joined: Jun 2007
Posts: 786
From: sf bay area, ca
Car Info: 06 WRX Wagon
the reason for this, is that at one point when i was downloading some WRC videos, i was being attacked about 400 times per day by people in countries ranging from finland to china and everywhere in between.

and last i heard, isnt NetBSD the most secure version of BSD available? i'm no unix guru, so i cant really say...
Old Dec 25, 2008 | 09:31 AM
  #7  
evsoul's Avatar
VIP Member
iTrader: (1)
 
Joined: Jul 2004
Posts: 5,588
From: Santa Rosa
Car Info: 2005 Unicorn
Originally Posted by not12listen
the reason for this, is that at one point when i was downloading some WRC videos, i was being attacked about 400 times per day by people in countries ranging from finland to china and everywhere in between.

and last i heard, isnt NetBSD the most secure version of BSD available? i'm no unix guru, so i cant really say...
What each distro of BSD is known for:
FreeBSD = The easiest to setup/use BSD
NetBSD = It will run on anything, **** even your toaster!
OpenBSD = security security security.

OpenBSD had like two exploits in 10yrs.
It's pretttty damn legit for security. You really can't beat it.
Old Dec 25, 2008 | 02:34 PM
  #8  
verc's Avatar
Registered User
iTrader: (12)
 
Joined: Jul 2003
Posts: 3,150
From: Palo Alto
Car Info: GT35R, Meth
Hah, glad to see there are other people building unneccessary home networks.

I have an absolutely overkill asa 5510 for my home IDS/VPN/FW setup http://www.cisco.com/en/US/products/...ries_home.html
Old Dec 25, 2008 | 09:50 PM
  #9  
MyNikonLens's Avatar
Registered User
iTrader: (2)
 
Joined: Jul 2007
Posts: 3,781
From: mobile home
Car Info: Porsche 911 GT3
I just purchased a SonicWall TZ190U.
Old Dec 25, 2008 | 11:47 PM
  #10  
evsoul's Avatar
VIP Member
iTrader: (1)
 
Joined: Jul 2004
Posts: 5,588
From: Santa Rosa
Car Info: 2005 Unicorn
Originally Posted by verc
Hah, glad to see there are other people building unneccessary home networks.

I have an absolutely overkill asa 5510 for my home IDS/VPN/FW setup http://www.cisco.com/en/US/products/...ries_home.html
i used to have a cisco pix 501 firewall haha. sooo unnecessary but i loved it.
Old Dec 26, 2008 | 05:14 AM
  #11  
Overbear's Avatar
Registered User
 
Joined: Mar 2008
Posts: 3,856
From: San Leandro, CA
Car Info: Forester XTi
My network is a bit more hardware based, listed from top to bottom in drill down...

1)D-link Cable modem flashed DOCSIS3.0 "cooked" beta rom
2)Sonicwall TZ170 25 license with advanced bios. Antivirus, antispam, and aggressive packet watch all turned on.
3)D-link wireless router set on the TZ170's DMZ (hardware isolated) and of course locked down with WPA2
4)Managed 1000/100/10 switch

As of right now my file server (windows 2003 machine, VM ware, 2 windows 2003 servers so far on it) is down for upgrades but will be back up soon. My exchange server sits on a rack in a colo as soon will my web server for my parked domains.
Old Dec 26, 2008 | 05:16 AM
  #12  
Overbear's Avatar
Registered User
 
Joined: Mar 2008
Posts: 3,856
From: San Leandro, CA
Car Info: Forester XTi
Originally Posted by MyNikonLens
I just purchased a SonicWall TZ190U.
you can not go wrong with a Sonicwall, they are in my opinion, one of the best router/hardware firewall combos out there.


Now if I could just justify the 10k cost of a barracuda unit for my mailserver
Old Dec 26, 2008 | 07:13 AM
  #13  
MyNikonLens's Avatar
Registered User
iTrader: (2)
 
Joined: Jul 2007
Posts: 3,781
From: mobile home
Car Info: Porsche 911 GT3
Originally Posted by Overbear
you can not go wrong with a Sonicwall, they are in my opinion, one of the best router/hardware firewall combos out there.


Now if I could just justify the 10k cost of a barracuda unit for my mailserver
we use barracuda for our mailserver and honestly it is the best i have ever seen. we did not have to buy it, just rent it.
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
67chevy
Wanted
0
Dec 6, 2004 08:47 AM
XLR8
Stereo & Security
6
Sep 7, 2004 07:16 PM
mybluheaven
Stereo & Security
6
Nov 17, 2003 05:41 PM
DaveWRX
Hawaii
2
May 12, 2003 12:41 AM
Jonnathan
Interior, Exterior & Lighting
4
May 5, 2003 08:38 PM


Thread Tools
Search this Thread

All times are GMT -7. The time now is 09:45 AM.