Linux Netfilter discussions
 help / color / mirror / Atom feed
* Distro Choice for iptables as Enterprise Firewall
@ 2006-12-31 16:31 Rackage | Randles
  2006-12-31 16:51 ` Maximilian Wilhelm
                   ` (3 more replies)
  0 siblings, 4 replies; 5+ messages in thread
From: Rackage | Randles @ 2006-12-31 16:31 UTC (permalink / raw)
  To: netfilter

Hi,

I'm new to iptables and this list so forgive me if this subject has been 
covered previously.

I'm sure this topic is a cause for much debate with no definitive answer 
however I would be glad to hear suggestions never the less.

What Distro's are recommended for deploying iptables as a dedicated 
firewall?

What server hardening steps would you recommend? (/Bastille?)

Thx in advance.

Regards

Ben







^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: Distro Choice for iptables as Enterprise Firewall
  2006-12-31 16:31 Distro Choice for iptables as Enterprise Firewall Rackage | Randles
@ 2006-12-31 16:51 ` Maximilian Wilhelm
  2006-12-31 16:58 ` Jan Engelhardt
                   ` (2 subsequent siblings)
  3 siblings, 0 replies; 5+ messages in thread
From: Maximilian Wilhelm @ 2006-12-31 16:51 UTC (permalink / raw)
  To: netfilter

Am Sonntag, den 31 Dezember hub Rackage | Randles folgendes in die Tasten:

Hi!

> I'm new to iptables and this list so forgive me if this subject has been 
> covered previously.

> I'm sure this topic is a cause for much debate with no definitive answer 
> however I would be glad to hear suggestions never the less.

> What Distro's are recommended for deploying iptables as a dedicated 
> firewall?

I like a small Debian installation for this purpose most.
The Debian base install is very small and you can easily remove unused
parts of it and add only the things you need (iptables, vlan, iproute,
younameit).
So you have full control on what is installed on your firewall and don´t
have to warry about unused daemons and stuff.
(I had some slightly bad experiences with a RedHat EL3 server where I
 had trouble to remove unused daemons...)

> What server hardening steps would you recommend? (/Bastille?)

Build your own kernel (currently you may want to wait to get some file
system corruption problems fixed before doing so :)) and activate
SE-Linux or patch your kernel with grsecurity[42].

Use iptables to restirct access to all needed services (ssh e.g.) and
configure your service as strict as possbile, e.g. allowing only users
with ssh-keys to access your box.

[42] http://www.grsecurity.net/

Ciao
Max
-- 
	Follow the white penguin.


^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: Distro Choice for iptables as Enterprise Firewall
  2006-12-31 16:31 Distro Choice for iptables as Enterprise Firewall Rackage | Randles
  2006-12-31 16:51 ` Maximilian Wilhelm
@ 2006-12-31 16:58 ` Jan Engelhardt
  2007-01-01  4:09 ` Shannon Roddy
  2007-01-02 20:51 ` Gary W. Smith
  3 siblings, 0 replies; 5+ messages in thread
From: Jan Engelhardt @ 2006-12-31 16:58 UTC (permalink / raw)
  To: Rackage | Randles; +Cc: netfilter


On Dec 31 2006 16:31, Rackage | Randles wrote:
>
> I'm new to iptables and this list so forgive me if this subject has been
> covered previously.

(Hint: Search the archives)

> I'm sure this topic is a cause for much debate with no definitive answer
> however I would be glad to hear suggestions never the less.

(See above)

> What Distro's are recommended for deploying iptables as a dedicated firewall?

It does not matter, netfilter is a kernel component, hence works with 
any thing even self-rolled init-only scripts (like WRT54G with Linux 
use).

	-`J'
-- 


^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: Distro Choice for iptables as Enterprise Firewall
  2006-12-31 16:31 Distro Choice for iptables as Enterprise Firewall Rackage | Randles
  2006-12-31 16:51 ` Maximilian Wilhelm
  2006-12-31 16:58 ` Jan Engelhardt
@ 2007-01-01  4:09 ` Shannon Roddy
  2007-01-02 20:51 ` Gary W. Smith
  3 siblings, 0 replies; 5+ messages in thread
From: Shannon Roddy @ 2007-01-01  4:09 UTC (permalink / raw)
  To: netfilter

On 12/31/06, Rackage | Randles <randles@rackage.com> wrote:

> What Distro's are recommended for deploying iptables as a dedicated
> firewall?
>

FWIW, I often use gentoo.


^ permalink raw reply	[flat|nested] 5+ messages in thread

* RE: Distro Choice for iptables as Enterprise Firewall
  2006-12-31 16:31 Distro Choice for iptables as Enterprise Firewall Rackage | Randles
                   ` (2 preceding siblings ...)
  2007-01-01  4:09 ` Shannon Roddy
@ 2007-01-02 20:51 ` Gary W. Smith
  3 siblings, 0 replies; 5+ messages in thread
From: Gary W. Smith @ 2007-01-02 20:51 UTC (permalink / raw)
  To: randles, netfilter

I've played around with using rPath.  It allows for distro's of 200mb
and runs with 64mb ram.  Bare install is just that, almost nothing but
basic kernel components and a few essentials.  

Now at the enterprise level you can also include the optional components
that you might want.

Seems to work well for me.

We also use RHEL4 for some of our bigger environments but the min
install there includes the kitchen sink.

> -----Original Message-----
> From: netfilter-bounces@lists.netfilter.org [mailto:netfilter-
> bounces@lists.netfilter.org] On Behalf Of Rackage | Randles
> Sent: Sunday, December 31, 2006 8:31 AM
> To: netfilter@lists.netfilter.org
> Subject: Distro Choice for iptables as Enterprise Firewall
> 
> Hi,
> 
> I'm new to iptables and this list so forgive me if this subject has
been
> covered previously.
> 
> I'm sure this topic is a cause for much debate with no definitive
answer
> however I would be glad to hear suggestions never the less.
> 
> What Distro's are recommended for deploying iptables as a dedicated
> firewall?
> 
> What server hardening steps would you recommend? (/Bastille?)
> 
> Thx in advance.
> 
> Regards
> 
> Ben
> 
> 
> 
> 
> 



^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2007-01-02 20:51 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-12-31 16:31 Distro Choice for iptables as Enterprise Firewall Rackage | Randles
2006-12-31 16:51 ` Maximilian Wilhelm
2006-12-31 16:58 ` Jan Engelhardt
2007-01-01  4:09 ` Shannon Roddy
2007-01-02 20:51 ` Gary W. Smith

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox