Bouncing this reply from LIH to ILUG-Cal --indra ----------- hello re. malay mitra's query: > I have been advised by h/w vendors like Cisco that > their PIX firewall is > much better than Linux squid firewall. well i'm not surprised cisco said that since their jobs depend on it ;-) the fact is: there's nothing u cannot do with the iptables firewall available with linux 2.4 (RH 7.1) IMHO u should do the following: 1. upgrade to kernel 2.4 2. use ipchains firewall (the default), along with tripwire intrusion detection system. 3. if u want more, switch off ipchains, switch on iptables - it offers stateful firewalling, packet mangling & NAT (better than checkpoint anyday or night). remember to turn off the IP_CONNTRACK_FTP module to prevent vulnerability during ftps. i think u should still be able to use squid for other things with either iptables/ipchains as firewall. u might find the following urls useful as a starting point: http://www.redhat.com/mailing-lists/redhat-watch-list/msg00199.html http://www.kalamazoolinux.org/presentations/20010417/ > I also want to put anti virus in Linux proxy so > that they can be caught > before they affect the Win 9x clients. how about AMaViS (A Mail Virus Scanner) downloadable at http://amavis.org/download u will still need ur favourite virus scanner (McAfee/Norton/etc) to go with it. can cisco match all this for Rs 200? (=cost of RH 7.1 CD) cheers vivek. __________________________________________________ Do You Yahoo!? Get email alerts & NEW webcam video instant messaging with Yahoo! Messenger http://im.yahoo.com -- To unsubscribe, send mail to [EMAIL PROTECTED] with the body "unsubscribe ilug-cal" and an empty subject line. FAQ: http://www.ilug-cal.org/help/faq_list.html
