Re: OpenBrick-E

Chris Knadle <[email protected]> Wed, 4 Feb 2004 17:27:52 -0500
Newsgroups gmane.comp.hardware.openbrick.general
Organization Aeroflex
Message-ID <[email protected]>
Hi Matjaz.

On Wednesday 04 February 2004 04:33 am, Matjaz Nartnik wrote:
> I've been recently searching the web for embedded
> server/firewall/router/... platform to which we could add aditional
> software packages and OpenBrick looks great for that. On HACOM online shop
> I've also found OpenBrickE platform, which is a little more suited for our
> application (3xLAN).

   Exactly.  There are two options for the three interfaces, also: 3xLAN 
RealTek interfaces, or 3xLAN Intel interfaces, one of which is a 1Gb/s 
interface.

> Since I'm new into the openbrick.org I would kindly ask if anyone can tell
> me what is the software support for the OpenBrickE. Do you have all these
> features and different distributions as for OpenBrick? Are there any
> arguments not to choose OpenBrickE?

   I'm personally using an installation of Debian for the OpenBrick-E that I'm 
using, on a 1 GB Lexar CF card.  _It's not cheap_ but otherwise it's 
excellent.  Setting up Debian (or another distro) on the CF card is a little 
tricky when it comes to installing the boot loader. 
   Also: running on a CF card has some issues - there is a lot of logging that 
goes on by default that writes to the CF card often, which CF doesn't 
tolerate very well from what I understand.  Thus, it's really desirable to 
set up a _ramdisk_ to hold often written information such as /var/log, and 
that's not trivial to set up and have automatically saved to disk at 
reboot/shutdown time.

   I'm personally using an iptables firewall built with Guarddog, but there 
are other alternatives (such as shorewall, etc..)

> Any other comments on comparisson of OpenBrick and OpenBrickE?

   The OpenBrick-E is an excellent piece of hardware.  One flaw is that it has 
to be completely dissasembled to get the CF card out/in of the machine.  If 
you get one and run on a CF card, cut a hole in the side of the case to slip 
in & out the CF card.
   We're also using a couple of OpenBrick-E machines at work for intrusion 
detection with Snort, which can be set up to use the "any" interface (as 
opposed to eth0, eth1, etc) and thus listen to all interfaces simultaneously.

   In short, it's a good choice but a little bit more tricky than simply a 
turnkey solution...  But it's also more fun that way.  ;-)

	- Chris

-- 
Chris Knadle
[email protected]