Bouncing this reply from LIH to ILUG-Cal

--indra
-----------

hello
  
re. malay mitra's query:
 
> I have been advised by h/w vendors like Cisco that
> their PIX firewall is
> much better than Linux squid firewall. 

well i'm not surprised cisco said that since their
jobs depend on it ;-)
the fact is: there's nothing u cannot do with the 
iptables firewall available with linux 2.4 (RH 7.1)

IMHO u should do the following:
1. upgrade to kernel 2.4
2. use ipchains firewall (the default), along with
tripwire intrusion detection system.
3. if u want more, switch off ipchains, switch on
iptables - it offers stateful firewalling, packet
mangling & NAT (better than checkpoint anyday or
night). remember to turn off the IP_CONNTRACK_FTP
module to prevent vulnerability during ftps.
i think u should still be able to use squid for other
things with either iptables/ipchains as firewall.

u might find the following urls useful as a starting
point:
http://www.redhat.com/mailing-lists/redhat-watch-list/msg00199.html
http://www.kalamazoolinux.org/presentations/20010417/

> I also want to put anti virus in Linux proxy so
> that they can be caught
> before they affect the Win 9x clients.

how about AMaViS (A Mail Virus Scanner) downloadable
at http://amavis.org/download
u will still need ur favourite virus scanner
(McAfee/Norton/etc) to go with it.

can cisco match all this for Rs 200? (=cost of RH 7.1
CD)

cheers

vivek.


__________________________________________________
Do You Yahoo!?
Get email alerts & NEW webcam video instant messaging with Yahoo! Messenger
http://im.yahoo.com

--
To unsubscribe, send mail to [EMAIL PROTECTED] with the body
"unsubscribe ilug-cal" and an empty subject line.
FAQ: http://www.ilug-cal.org/help/faq_list.html

Reply via email to