Paolo Andretta <[email protected]> wrote:

> The advantage of a dedicated firewall distro is that it is usually 
> hardened and that there are tools that can be very useful when you need 
> to solve some problem (traffic/system/... graphs, useful add-on, ...).

As the saying goes, it's 6 of one, half a dozen of the other.
While a specialist distro has those advantages, it can also be a disadvantage 
having a distro/tools you aren't familiar with. And add in that such 
unfamiliarity may mean you accidentally break something that means it's no 
longer as hardened as you thought and there's potential for problems. Neither 
is "right" or "wrong" - just two options with pros and cons both ways.

> What and which do you usually install?

Depends on my needs.
I have boxes at work that only really run the base distro plus ssh, shorewall, 
rsync, and ntp as a client only (to keep the clock in sync). All my gateways 
run one or more bits of RRD Tools - typically the gateways only use RRD Daemon 
to send the updates to a central logging server. One pair also run keepalived 
so as to run in an active/backup pair.
If you make the default policies all drop (or deny where you want to get an 
explicit rejection rather than timeout) and allow the traffic you need, it's 
fairly easy to keep the visible footprint to a minimum.


------------------------------------------------------------------------------
The best possible search technologies are now affordable for all companies.
Download your FREE open source Enterprise Search Engine today!
Our experts will assist you in its installation for $59/mo, no commitment.
Test it for FREE on our Cloud platform anytime!
http://pubads.g.doubleclick.net/gampad/clk?id=145328191&iu=/4140/ostg.clktrk
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to