Re: alternatives to m0n0

Lee Sharp <[email protected]> Mon, 16 Feb 2015 11:20:03 -0600
Newsgroups gmane.comp.security.firewalls.m0n0wall
Message-ID <[email protected]>
On 02/16/2015 11:01 AM, Thomas Sprinzing wrote:
> Dear all,
>
> maybe it’s worth while to open another thread for those of you feeling stranded.

Not a bad plan... :)

I also have been doing this a while, and have a lot of firewalls out 
there on single core machines with 256meg flash on board.  (So OpenSense 
is out)

I used to play a bit with pfSense, and recommend it in some cases, 
but...  Chris partnered with a new guy, and the new guy is the cause of 
all of the woes you have mentioned.  He is combative, and 
unprofessional, and is constantly looking to maximize revenue at the 
expense of everything else.  I had worked with Chris a few times over 
the years, so when his partner blasted me on LinkedIn, I tried to 
contact Chris privately to find out what was going on.  I heard nothing, 
so I suspect he is contractually enjoyed from saying anything.  This 
means that I can not trust Chris (who I still consider a very good guy) 
to keep pfSense trustworthy.  So pfSense is off the table.

I have also worked with FreeNAS and NAS4Free, and seen how additional 
complexity is not good when major vulnerabilities come down the pipe. 
So, to me, I need a m0n0wall fork.  Not because the current version is a 
problem, but to give assurances that the code can be fixed.

Right now, however, I am doing nothing.  I am waiting to see if Manual 
will change his mind, or let others take the project.  (Yes, I will 
assist, if asked)  I do not suspect he will, :) but I want to give him 
that time.  He has given us so much, and he deserves that.

But if not, I am looking at who could join me in a fork.  I can set up 
the hosting needed, and I can manage a project.  But I am a poor coder. 
:)  If some of the other devs are interested, we could do a small fork. 
  It would not be too hard, as there is little to fix.  We do not want 
to make m0n0wall biger, or we would just use OpenSense. :)  We just need 
to fix bugs, and upgrade some things. (WebGUI, and VPN options come to mind)

			Lee