Rod,

Pmfirewall is fine for a workstation on a local network that also has a 
dedicated firewall, but I would not recommend it for an 
Internet-accessible server. By dedicated firewall, I am talking a separate 
box that only does firewalling and nothing (or almost nothing) else. I use 
FreeSco (www.freesco.org) for my dedicated firewall. It is based on an 
older Linux kernel, boots off a floppy, and runs on my 486 with 16MB RAM 
in a virtual RAM disk -- so once it is booted up, I pull out the floppy, 
making the machine virtually unhackable.

I say unhackable, because there are no drives that can be mounted, and 
therefore even IF someone manages to crack the system and "install" a 
backdoor, a simple reboot from diskette wipes the RAM disk and gives me a 
clean system once again. Further, because the system is dedicated, there 
are no other Internet services running that are known security risks. 
Also, it constantly shows me its system log on the monitor, so I always 
know when the firewall is running properly, and if anything strange is 
happening (like someone scanning my network for open ports, etc.).

I also run pmfirewall on my workstations, because if someone manages to 
get into my firewall, then they still have another local firewall to get 
past if they really want to reach my important systems.

Hope this helps,
Dave

On Friday 18 May 2001 07:22, thus spake Rod Upfold:
> Right now I am using PMFirewall....mainly because it was used by
> Mandrake in their firewall tutorial....but is there a better firewall
> than PMFirewall and I am also not too sure if the firewall is up and
> running...ther is no indication if it is running or not.
>
> What is your personal choice of a firewall ( I am using a DSL
> connection) and does your choice give you some kind of indication that
> it is up and running...??
>
>
>
> Rod
>
>      ********************************************

-- 
"Nihil tam munitum quod non expugnari pecuna possit."
- Marcus Tullius Cicero, 106-43 B.C.

Reply via email to