Jason Costomiris on Thu, 30 Dec 1999 15:51:15 -0500 (EST)


[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]

Re: [Plug] Firewalls


On Thu, Dec 30, 1999 at 11:18:38AM -0500, Michelle Weber wrote:
: I would like to get some of your opinions on firewalls, which do you think
: is the best platform? 


: WinNT Server 4, 

In reality, NT can be made to mostly sit, shut up, and work.  It involves
choosing very good name-brand parts from solid companies that produce
good solid drivers, for the most part.  That means NICs from players
like 3com and Intel.  That means video from people like Diamond (yes,
they have a couple of cheap video cards, like around $30 in AGP).  NT 
can even be turned into something reasonably secure by doing little things
like applying service packs and hotfixes, then remove services like

Server
Workstation
NetBIOS Helper
WINS Client
Computer Browser

Yes, NT will boot without those.  By doing that, you essentially turn NT
into an IP router that looks like Windows.  NT will even tell you that
"Windows NT Networking is not installed.", and it's correct, there is no
Windows networking, just IP.  After that, install something like FireWall-1,
or any other NT firewall.

: Win2000 Server, 

I wouldn't touch it yet.

: Linux, or FreeBSD?

Both fine choices for a small LAN that doesn't have huge feature set 
requirements.  Check Point has a beta of FireWall-1 for Linux right now,
today.

Most of the "appliance" vendors have chosen to base their embedded OS's on
FreeBSD.  This includes players like Alcatel and Nokia.

: I'm inclined to go with Linux, I've heard nothing but good
: things about FreeBSD as a firewall. Your thoughts?

Ipchains is technically more advanced.  Use what you like.  YMMV.

-- 
                 Jason Costomiris <><
            Technologist, cryptogeek, human.
jcostom {at} jasons {dot} org  |  http://www.jasons.org/

_______________________________________________
Plug maillist  -  Plug@lists.nothinbut.net
http://lists.nothinbut.net/mail/listinfo/plug