Re: alternatives to m0n0
Thomas Sprinzing <[email protected]> Wed, 18 Feb 2015 16:59:36 +0100
| Newsgroups | gmane.comp.security.firewalls.m0n0wall |
|---|---|
| Message-ID | <[email protected]> |
>=20 > And that is a good reason. But I have dozens of firewalls out there = running fine with lots of head room on m0n0wall, that will not at all = support OpenSense. No, there is a place for a small build firewall. Yes, and again: As there are builds of pfsense out there, that run on WRAP, and as = opnsense is a fork of said pfsense, i see no hindrance in being able to = wrangle and prune opnsense into a small size embedded firmware for sme = and home access routers. Just don=92t expect miracles in performance = (which you don=92t). Given that, security-wise, the threat model for such devices and the = speed of discovery-release-exploit has developed to the worse lately, it = makes much more sense in my opinion to put the collective effort into a = project which is based on current base packages rather than keeping the = old thing afloat. Especially so, when your time and expertise is = limited. Also, i think this is the best reason to look after your customers and = talk to them. Throw yourself into learning that opnsense stuff, grok the = thing, and then preconfigure and mail the box out to your customer=92s = site. Worst case: it=92s plug and play, i did that with the one and only = other box i supported outside. In fact, the old wrap still sits in the = cabinet, just in case, i tell them to unplug the black thing and plug = the red thingamajic - perfectly interoperable. Best case: your customer = will be happy you called, because, well, if you could get them another = contract with faster speed, more secure and whatnot, and did you = remember, that sales guy xyz, he doesn=92t work for them anymore, if you = could make sure that he doesn=92t have access=85.. So me, for my part, i=92ll be supporting the opnsense movement. Dealing = with vintage i will restrict to my favorite pastime, an old and trusted = four wheeler. cheers Thomas