Firewall Wizards mailing list archives

Re: linux firewal question (newbie)


From: David Lang <dlang () diginsite com>
Date: Wed, 7 Oct 1998 17:50:19 -0700 (PDT)

-----BEGIN PGP SIGNED MESSAGE-----

one major performance item to watch with the toolkit, make sure you are
runnig the proxys as daemons not from inetd. there is a HUGE overhead when
the proxy starts

David Lang


On Wed, 7 Oct 1998, Joseph S. D. Yao wrote:

Date: Wed, 7 Oct 1998 14:42:36 -0400 (EDT)
From: Joseph S. D. Yao <jsdy () cospo osis gov>
To: tromh () yahoo com
Cc: firewall-wizards () nfr net, camoa () geocities com
Subject: Re: linux firewal question (newbie)

I need to choice the best firewal option for linux, which is it?

Well ipfwadm is not a FW but a command .
I'm not a specialist, what i think is that FWTK is nice but not uses
lots of system ressources . For example ;, if u put 30 computers and a
FW , proxy beetween them and internet , u will see the rate really
slow down !!!

SQUID SEEMS to be really better . 

Like i said i'm not a specialist and i don't know evrything .

If u speak french i wrote a documentation on FWTK security and
installation u can find at www.altern.org/trom

Hardware is (relatively) cheap.  Figure out where your bottlenecks are
(NIC?  RAM?  CPU?), and get something an order of magnitude better.

Squid only passes HTTP, AFAIK.  It fits nicely in as a part of the FWTK
- which is just a toolkit to build a firewall, remember?  I put lots of
tools into any pre-fab toolkit I get.

--
Joe Yao                               jsdy () cospo osis gov - Joseph S. D. Yao
COSPO/OSIS Computer Support                                   EMT-A/B
-----------------------------------------------------------------------
This message is not an official statement of COSPO policies.



-----BEGIN PGP SIGNATURE-----
Version: PGP for Personal Privacy 5.0
Charset: noconv

iQEVAwUBNhwMTT7msCGEppcbAQHRBQf+OCrkA4l9fROGR+BGkJ82SAomdmSEVdAf
BxYvqRUnvmelAQGtV4chuskpmVtmMh2dvNjS3jGkZOMhGTv9rjXNGiEGaUoabyIR
cPCY2nPn/ME4xLBUTi0emwcuUfjXTJ4+JnnBj2All65POw50xbhF3ufp38FAHvnM
VRsttKgLOFvQ+g9S8WHk/ku34plZZYqWI4J5a6qrk0BsqWxaiOkyzLKARAJUmkEG
QicwdgB9gEdmD9UIDsgQuEGCW6znCjb4Rs0kyfB3CtKNxnK9PJkBZ3UOMwZdozl4
QITLczGnYj+hx2dK/b7SndKs9bMVd2an7WSxU3pxWOFZjXdqPl0sVQ==
=0WQl
-----END PGP SIGNATURE-----



Current thread: