Firewall Wizards mailing list archives

Re: Firewall: dedicated equipament x Unix workstation


From: sedwards () sedwards com
Date: Tue, 13 Oct 1998 17:20:01 -0700 (PDT)

On Sun, 11 Oct 1998, Matthew Patton wrote:

My firewall requires precisely one 1.44MB floppy (actually less) to
operate. Local disk is optional and is used strictly for logging with flags
SAPPND and securelevel=2. It's built entirely on freeware and trash (486/66
EISA computer with lots of NICs) the IT department deemed useless. It
doesn't even tickle the CPU with 10Mbit ethernet, let alone a T1. As
currently configured there are no userlevel endpoint services on it though
putting bind on would be quite easy. Remote mgmt is via SSH on the internal
interface only or optional serial line. It won't stop anything a packet
sniffer can't (eg. protocol attacks) but it does a fine job nonetheless and
costs thousands less than any Cisco router or PIX or Checkpoint's favorite
solution.

How about some more details -- OS, what additonal software, etc.

Thanks in advance,
------------------------------------------------------------------------
Steve Edwards      sedwards () sedwards com      Voice: +1-760-723-2727 PST
Newline            Pager: +1-760-740-1220           Fax: +1-760-731-3000



Current thread: