Re: [CentOS] Dedicated Firewall/Router

2012-01-17 Thread Rudi Ahlers
On Tue, Jan 17, 2012 at 9:55 AM, Laurent Wandrebeck
l.wandreb...@gmail.com wrote:
 On Mon, 16 Jan 2012 18:18:26 -0600
 Tom Bishop bisho...@gmail.com wrote:

 I would get a dell r210 from the outlet site and then load pfsense,
 been running in multiple locations, solid and works great.
 Do NOT use pfsense if you have to use realtek cards. I used to (1.2.3
 and 2.0.1), and lost connection regularly, need to reboot to get it
 back…
 Flee realtek as much as you can :)

You shouldn't be using realtek NIC's in a production, or even just a
large-ish server environment in anycase. Rather use Intel.

Back to the topic though, how does one guarantee 100% uptime on the
firewall level when you use a standard dedicated server? Even if the
server (Dell / Intell / SuperMicro / you name it...) has redundant
PSU's and HDD's, there could still be hardware failure. And, unless
you buy 3 or 4 at a time, you may run into a where once you pop the
HDD into a new (standby?) chassis that something may not be compatible
and the firewall might be down for a few minutes, or even hours while
you search for a solution on the internet, or with the hardware
vendor.




-- 
Kind Regards
Rudi Ahlers
SoftDux

Website: http://www.SoftDux.com
Technical Blog: http://Blog.SoftDux.com
Office: 087 805 9573
Cell: 082 554 7532
___
CentOS mailing list
CentOS@centos.org
http://lists.centos.org/mailman/listinfo/centos


Re: [CentOS] Dedicated Firewall/Router

2012-01-17 Thread Rainer Duffner
Am Tue, 17 Jan 2012 10:02:01 +0200
schrieb Rudi Ahlers r...@softdux.com:


 Back to the topic though, how does one guarantee 100% uptime on the
 firewall level when you use a standard dedicated server? 
 


pfSense offers failover via CARP



___
CentOS mailing list
CentOS@centos.org
http://lists.centos.org/mailman/listinfo/centos


Re: [CentOS] Dedicated Firewall/Router

2012-01-17 Thread Lars Hecking
Jason T. Slack-Moehrle writes:
 Hi All,
 
 I want to build a dedicated firewall/router as I am launching a NPO and I can 
 host this in my garage. (Comcast offered me a 100 x 20 circuit for $99/mo 
 with 5 statics)
[...] 
 Thoughts, opinions, suggestions are welcome as to what to do!
 
 http://www.openbsd.org/

___
CentOS mailing list
CentOS@centos.org
http://lists.centos.org/mailman/listinfo/centos


Re: [CentOS] Dedicated Firewall/Router

2012-01-17 Thread Steve Thompson
On Mon, 16 Jan 2012, Jason T. Slack-Moehrle wrote:

 I want to build a dedicated firewall/router as I am launching a NPO and 
 I can host this in my garage. (Comcast offered me a 100 x 20 circuit for 
 $99/mo with 5 statics)

I use two Dell R310's in a master/backup setup with shorewall and 
keepalived.

-s
___
CentOS mailing list
CentOS@centos.org
http://lists.centos.org/mailman/listinfo/centos


Re: [CentOS] Dedicated Firewall/Router

2012-01-17 Thread Lorenzo Martínez Rodríguez

CentOS Linux + Fwbuilder FTW!

El 17/01/12 14:38, Steve Thompson escribió:
 On Mon, 16 Jan 2012, Jason T. Slack-Moehrle wrote:

 I want to build a dedicated firewall/router as I am launching a NPO and
 I can host this in my garage. (Comcast offered me a 100 x 20 circuit for
 $99/mo with 5 statics)
 I use two Dell R310's in a master/backup setup with shorewall and
 keepalived.

 -s
 ___
 CentOS mailing list
 CentOS@centos.org
 http://lists.centos.org/mailman/listinfo/centos




-- 


Lorenzo Martinez Rodriguez

Visit me:   http://www.lorenzomartinez.es
Mail me to: lore...@lorenzomartinez.es
My blog: http://www.securitybydefault.com
My twitter: @lawwait
PGP Fingerprint: 97CC 2584 7A04 B2BA 00F1 76C9 0D76 83A2 9BBC BDE2

___
CentOS mailing list
CentOS@centos.org
http://lists.centos.org/mailman/listinfo/centos


Re: [CentOS] Dedicated Firewall/Router

2012-01-17 Thread dnk
On Tuesday, January 17, 2012, Lorenzo Martínez Rodríguez 
lore...@lorenzomartinez.es wrote:

 CentOS Linux + Fwbuilder FTW!

 El 17/01/12 14:38, Steve Thompson escribió:
 On Mon, 16 Jan 2012, Jason T. Slack-Moehrle wrote:

 I want to build a dedicated firewall/router as I am launching a NPO and
 I can host this in my garage. (Comcast offered me a 100 x 20 circuit for
 $99/mo with 5 statics)
 I use two Dell R310's in a master/backup setup with shorewall and
 keepalived.

 -s
 ___
 CentOS mailing list
 CentOS@centos.org
 http://lists.centos.org/mailman/listinfo/centos




 --


 Lorenzo Martinez Rodriguez

 Visit me:   http://www.lorenzomartinez.es
 Mail me to: lore...@lorenzomartinez.es
 My blog: http://www.securitybydefault.com
 My twitter: @lawwait
 PGP Fingerprint: 97CC 2584 7A04 B2BA 00F1 76C9 0D76 83A2 9BBC BDE2

 ___
 CentOS mailing list
 CentOS@centos.org
 http://lists.centos.org/mailman/listinfo/centos


Sevonded'
___
CentOS mailing list
CentOS@centos.org
http://lists.centos.org/mailman/listinfo/centos


[CentOS] Dedicated Firewall/Router

2012-01-16 Thread Jason T. Slack-Moehrle
Hi All,

I want to build a dedicated firewall/router as I am launching a NPO and I can 
host this in my garage. (Comcast offered me a 100 x 20 circuit for $99/mo with 
5 statics)

I used to run Untangle, but as of version 9, you are forced to use their build 
in protocol policies versus the firewalling I am used to (Deny All and then 
opening holes for specific IP's, etc).

There are so many firewall distros to choose from. FireStarter, IPCOP, etc.

The box I was going to use is a P4, 3GB RAM, 3 GB NICS.

I could always use a beefier box also if there was really a need to for such a 
task. 

I am used to some Cisco PIX boxes and they just seem fast on hardly any specs. 
I had a PIX 525 that only had 256mb of RAM about 8 years ago and it was a 
rockstar.

Thoughts, opinions, suggestions are welcome as to what to do!


-Jason
___
CentOS mailing list
CentOS@centos.org
http://lists.centos.org/mailman/listinfo/centos


Re: [CentOS] Dedicated Firewall/Router

2012-01-16 Thread Miguel Medalha

 I want to build a dedicated firewall/router as I am launching a NPO and I can 
 host this in my garage. (Comcast offered me a 100 x 20 circuit for $99/mo 
 with 5 statics)

 Thoughts, opinions, suggestions are welcome as to what to do!

http://www.pfsense.org/

___
CentOS mailing list
CentOS@centos.org
http://lists.centos.org/mailman/listinfo/centos


Re: [CentOS] Dedicated Firewall/Router

2012-01-16 Thread Tom Bishop
I would get a dell r210 from the outlet site and then load pfsense,
been running in multiple locations, solid and works great.

On 1/16/12, Jason T. Slack-Moehrle slackmoeh...@gmail.com wrote:
 Hi All,

 I want to build a dedicated firewall/router as I am launching a NPO and I
 can host this in my garage. (Comcast offered me a 100 x 20 circuit for
 $99/mo with 5 statics)

 I used to run Untangle, but as of version 9, you are forced to use their
 build in protocol policies versus the firewalling I am used to (Deny All and
 then opening holes for specific IP's, etc).

 There are so many firewall distros to choose from. FireStarter, IPCOP, etc.

 The box I was going to use is a P4, 3GB RAM, 3 GB NICS.

 I could always use a beefier box also if there was really a need to for such
 a task.

 I am used to some Cisco PIX boxes and they just seem fast on hardly any
 specs. I had a PIX 525 that only had 256mb of RAM about 8 years ago and it
 was a rockstar.

 Thoughts, opinions, suggestions are welcome as to what to do!


 -Jason
 ___
 CentOS mailing list
 CentOS@centos.org
 http://lists.centos.org/mailman/listinfo/centos

___
CentOS mailing list
CentOS@centos.org
http://lists.centos.org/mailman/listinfo/centos


Re: [CentOS] Dedicated Firewall/Router

2012-01-16 Thread Ljubomir Ljubojevic
On 01/17/2012 01:11 AM, Jason T. Slack-Moehrle wrote:
 Hi All,

 I want to build a dedicated firewall/router as I am launching a NPO and I can 
 host this in my garage. (Comcast offered me a 100 x 20 circuit for $99/mo 
 with 5 statics)

 I used to run Untangle, but as of version 9, you are forced to use their 
 build in protocol policies versus the firewalling I am used to (Deny All and 
 then opening holes for specific IP's, etc).

 There are so many firewall distros to choose from. FireStarter, IPCOP, etc.

 The box I was going to use is a P4, 3GB RAM, 3 GB NICS.

 I could always use a beefier box also if there was really a need to for such 
 a task.

 I am used to some Cisco PIX boxes and they just seem fast on hardly any 
 specs. I had a PIX 525 that only had 256mb of RAM about 8 years ago and it 
 was a rockstar.

 Thoughts, opinions, suggestions are welcome as to what to do!


ClearOS, RHEL based Firewall/Router/Server with Web GUI. Simple to use, 
and it is like working on CentOS.

http://www.clearfoundation.com/


-- 

Ljubomir Ljubojevic
(Love is in the Air)
PL Computers
Serbia, Europe

Google is the Mother, Google is the Father, and traceroute is your
trusty Spiderman...
StarOS, Mikrotik and CentOS/RHEL/Linux consultant
___
CentOS mailing list
CentOS@centos.org
http://lists.centos.org/mailman/listinfo/centos


Re: [CentOS] Dedicated Firewall/Router

2012-01-16 Thread Laurent Wandrebeck
On Mon, 16 Jan 2012 18:18:26 -0600
Tom Bishop bisho...@gmail.com wrote:

 I would get a dell r210 from the outlet site and then load pfsense,
 been running in multiple locations, solid and works great.
Do NOT use pfsense if you have to use realtek cards. I used to (1.2.3
and 2.0.1), and lost connection regularly, need to reboot to get it
back…
Flee realtek as much as you can :)


pgpfJPBr2Z0S7.pgp
Description: PGP signature
___
CentOS mailing list
CentOS@centos.org
http://lists.centos.org/mailman/listinfo/centos