Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×
Security

Bootable CDROM-based Firewalls? 50

DNapalm asks: "I work at a small local ISP that is in desperate need of a firewall. We don't have much of a budget, so a hardware-based solution (which I'd prefer) really isn't an option. I've been searching around the web for firewall distributions, and I know what I am looking for. I'd like a boot CD (no install required, no filesystem hacking, just reboot) that stores the configuration on a floppy (that we can easily write protect). It should have a web interface and be able to log to a hard drive or some other machine. Some distributions I've found that seem close are Sentry Firewall, Devil-Linux, NetBoz, ClosedBSD, and Keeper Linux. Has anyone used these? Can you give recommendations? Any help would be appreciated."
This discussion has been archived. No new comments can be posted.

Bootable CDROM-based Firewalls?

Comments Filter:
  • gogole (Score:2, Insightful)

    by isorox ( 205688 )
    You cant afford $60 [amazon.com]? Or your want a real router?

    Google/Linux router floppy [google.com] gives Linux router project [linuxrouter.org]
  • LEAF (Score:4, Informative)

    by SIGBUS ( 8236 ) on Sunday November 24, 2002 @08:31AM (#4742642) Homepage
    LEAF [sourceforge.net], with several versions, would be a good starting point. One variant in particular would be Dachstein-CD [sourceforge.net], which boots off a CD and uses a floppy to back up configuration changes. Note that the Dachstein releases are 2.2/ipchains-based, while Bering [sourceforge.net], which is floppy-based, is a 2.4/iptables system.

    I'm using a floppy-based Bering system where I work as a multi-ISP router/firewall, and it works quite well.

  • by Anonymous Coward on Sunday November 24, 2002 @08:40AM (#4742658)
    For those who wish to avoid the ISP that can't be bothered to actually administer a firewall:

    Synergy Networking
    http://www.synergycorp.com
    1780 SW 43 Ave.
    Fort Lauderdale, FL 33317
    Phone: (954) 792-1866
    Fax: (954) 791-4214
    E-mail: webmaster@synergycorp.com

    Sorry to post anonymously. I'm sick to death of irresponsible ISPs who have no clue how the technology they work with actually works. You're running a goddamned ISP, invest some time into understanding what that firewall is before deploying it.

    I shouldn't be surprised. This ISP is proud to have a "less is more" policy for website design. Hell, right below their claim to have secure web pages, they proudly state their FrontPage support.
    • by Anonymous Coward
      The buzzword "synergy" kills me. What exactly are they synergizing there anyways? It makes me think of that Simpsons quote:

      "Proactive? Paradigm? Aren't these just buzz words that stupid people use to sound smart?"
  • by matts.nu ( 94472 ) on Sunday November 24, 2002 @09:13AM (#4742711) Homepage
    You should really list your needs before you pick a firewall.

    Do you just need a packet filter, to block incoming SYN packets?

    Or are looking at an application firewall with anti-virus e-mail scanning, web caches, VPN's, seperate DMZ's for your servers, authentication with OTP's and tokens, etc?

    Different needs. Different solutions.

    How much staff do you have? Any *nix experts?
  • SuSE Firewall (Score:3, Informative)

    by Khazunga ( 176423 ) on Sunday November 24, 2002 @09:27AM (#4742741)
    You'll want your security advisories delivered to your doorset, with quick and easy updates. If yor time is worth a dime, go for a commercial distro. I'd use SuSE:

    http://www.suse.com/us/business/products/suse_busi ness/firewall/index.html [suse.com]

    • A firewall should only very rarely need security updates. You aren't running services on it, right? At most an SSH that is only facing inward....
      • True. But off the top of my head, I remember at least three recent updates that affected ssh: one for glibc, which allowed privilege escalation, one for libzip for buffer overruns, and one for openssh itself -- which never was clear if it would allow remote compromise.

        Few services == lower maintenance != no maintenance.

  • Gibraltar (Score:4, Informative)

    by acaird ( 530225 ) on Sunday November 24, 2002 @09:57AM (#4742824)
    Gibraltar [gibraltar.at] is pretty much what you just described. It worked very well for me in the past, although it looks like development has slowed down (no updates, at least to the free version, in over a year).
    • Are you sure you are not just checking an out of date mirror. Gibraltar 0.99.5 was released only a couple of months ago (ie, September 2002).
  • Check out the hot deal forums over at sites like Fatwallet.com [fatwallet.com] or Anandtech [anandtech.com]. Here's a thread [anandtech.com] about cheap firewalls from the latter.
  • Coyote Linux! [coyotelinux.com]

    I know it's not supposed to be CDROM based, but it is smaller and easier. They've stopped developement on it, so it's pretty stable. You can hack it to run off a CDROM, but it's just as good from a floppy. It's part of the Linux Router Project, and it acts as a pretty good firewall too. It uses IP chains and IP masquerade, so you can do as much or as little configuration as you want.

  • Our firewall (Score:3, Interesting)

    by Peter H.S. ( 38077 ) on Sunday November 24, 2002 @12:37PM (#4743428) Homepage
    is a floppy based solution from http://www.zelow.no/floppyfw

    We have a 4Mbit/4Mbit HDSL line, and around 320 nodes. (I am part of a team, that runs a small time volunteer ISP: the whole street I live in, joined together to get good Internet access for a reasonable price; Linux all the way, yaeh!)

    floppfw is a quite nice distro, it has loads of add-on packages: VPN(PPTP, Cisco, Intel etc), PPP, ssh etc. It is rock solid and has a high performance (used it for 3-4 years without problems)

    There is also a powerfull GUI for configuring it: http://www.fwbuilder.org/
    But is very simple to maintain and costumize without. You just mount -o the image, edit, unmount. Rolling and using your own kernel is also quite easy (we use NAT, and some NAT helper modules are outside the kernel).

    The downside:
    No changing the firewall rules on the fly.
    Changing rules or upgrading, means a reboot lasting a minute or so.
    We have a spare box (can be used as firewall or proxy, dhcp server if necessary), so by changing the default gateway, we can avoid loss of Internet connectivity, though it means that people cannot access our web-site in the mean time, but we can live with that, other may not).

    We also use the spare box, as a testing unit for new firewalls, so we can be confident that it works before it is put into production.

  • LEAF! (Score:2, Interesting)

    by erth64net ( 47842 )
    I use LEAF [sf.net], and have since they forked their code from the original "Cop Killer" Dave at linuxrouter.org. The Bering floppy and CD images are the best, with tools like GRSecurity [grsecurity.org] (enhanced kernel security), Shorewall [shorewall.net] (great tool for configuring ipchains, for every possible setup), FreeS/WAN [freeswan.org] (IPSEC/VPN tools), and a 2.4 based kernel that works great on a 486. The best thing is the developers over at LEAF, keep their packages current.

    At present, I have 6 offices, hanging off this setup, with each one running the VPN daemon as well. There are plans in place (installation stage) to get 6 more internet circuits for the rest of our offices, making making for a total of 12 offices running off this code. It's excellent code, with a very well integrated setup, using standard tools, and gobs of documentation.

    The best thing; except for the main office (which uses a P166), everyone else will be running their firewall and VPNs on pentium 100's or 120's, with 24 or 32 megs of ram.
  • Offers their product for download, and includes a Windows VPN client along with it. Bootable CD, etc.
  • I'm really surprised - there are posts here mentioning some truly obscure solutions, but no one's mentioned one of the most popular: Smoothwall [smoothwall.co.uk] is all-CD-based, and is certainly one of the most widely used CD-based firewall distros on the net. The link above is to Smoothwall's corporate, supported version, but a less featureful free version is available. It used to integrate well with the Dan's Guardian content filter, until Dan joined Smoothwall, so they no longer tell you how to mke the two work together, since that would compete with their commercial offering. Still, their pricing seems reasonable, and while not a state-of-the-art firewall, it's no worse than all the other stateful packet filters out there. (Ultimately, that's just not a very good way to provide security, which is why SPFs are no longer permitted by the military.)

    If you don't have to have it run from CD, you should probably check out T-Rex [opensourcefirewall.com] (NOT a stateful packet filter, but the free version is lagging a bit), or, if you need a firewall combined with other functions (such as serving files, mail, web, etc.) then check out e-smith [e-smith.org] or ClarkConnect [clarkconnect.com].
  • Floppyfw [zelow.no] is actually a (surprise!!) floppy based distro. But there is also an ISO image. I use it at home. I have friends that also use it for their networks. Works good. Easy to setup. From the webpage, the author claims he has used it for networks with thousands of computers. I wouldn't doubt it.
  • I use Devil Linux on one network that I administer. The docs are a bit scant and mostly point you to the docs for each service you install but overall I think the firewall is excellent. It's built from Linux From Scratch. All but the config files are on the CD. The config files are on a write protected floppy. There is support for most common services for those shops that can't afford a firewall and mail server for example. I know this isn't the best idea but it is a practical reality for many. At least Devil Linux offers chroot jails and since a reboot sets the server back to the original install state (except for any mail spool that is saved on a disk) the exposure is fairly low. There is also support for FirewallBuilder scipts and most common services . I think Devil Linux is at least worth consideration. It's actively developed and GPL'ed.
  • Gnatbox (Score:2, Informative)

    by Wicked Panda ( 10814 )
    http://www.gta.com

    Simple floppy based firewall, with GUI for those who want it. Easily configured, and rated highly by several publications. Logs via syslog to another system. Can do email and dns proxying if you need it. Doesn't do CDROM, but you can do flash memory.

    Basically, a BSD derived firewall that was split from the tree a few years ago. They have an active development effort, and sell commercial products just for your situation. Commercial versions of Gnatbox are not cheap, but there is a good installed base, and a good mailing list that will help with stuff.
  • 1. Why boot from the CD? Why not boot from the hard drive? Are you really on a HD-less PC, and can't afford to buy a small drive? I can't imagine when this solution is viable. It would make sense if you were in a highly fluid environment, but in most production environments, you can afford a cheap PC with a hard drive.

    2. You can boot your linux/bsd/whatever firewall using PXE or some other environment.

    3. If you are deadset on the CD solution, do you need a floppy thrown in the mix as well? a CD is dirt cheap these days, you can just burn another copy with the new settings. Or just use a rewritable CD. Or read your settings from the network.. floppy disks die nasty deaths for various reasons.

  • fli4l [fli4l.de] plus OPT_BOOTCD [fli4l.de]. You may also want to read one of the HOWTOs fli4l auf CDR [fli4l.de] or isofli4l [foken.de].

    fli4l is a german language project, but fli4l itself has also an english documentation.

If you want to put yourself on the map, publish your own map.

Working...