Fw: Debian as My home firewall/router
Renaud (Ron) OLGIATI <renaud-9qJ39Kf4vhh95CE/QLhGvQK61p16E/[email protected]>
| Newsgroups | gmane.comp.security.ipcop.user |
|---|---|
| Message-ID | <[email protected]> |
In reply to a query about configuring Debian as a firewall, I suggested using IPCop instead. This provoked the heated reply I am forwarding below. Would any IPCop guru care to comment ? Cheers, Ron. Begin forwarded message: Reco <[email protected]> wrote: > > I know that is possible to build a firewall using Debian. > It is possible, but why go to the bother when you have dedicated distributions like IPCop that come ready to go, and are by design more secure than a specially-configured Debian will be. Please. "Out-of-the-box" IPCop (version 2.1.8 I just grabbed from the Sourceforge) does have: 1) No meaningful DNSSEC capability. 2) Presence of libfontconfig.so *and* fonts for no good reason. 3) Bunch of questionable quality root-owner SUID binaries in /usr/local/bin, intended to be called from Web-interface. 4) Lack of any pre-installed IDS. 5) Outdated kernel 3.4, configured *without* SELinux, Apparmor or tomoyo support. Oh, did I mention that *primary* download mirror for this distribution is the Sourceforge? IPCop can be an interesting solution for a host on an internal network, which nobody intends to poke, but suggesting putting *this* to serve as a firewall from an Internet is a joke. Reco ------------------------------------------------------------------------------ Site24x7 APM Insight: Get Deep Visibility into Application Performance APM + Mobile APM + RUM: Monitor 3 App instances at just $35/Month Monitor end-to-end web transactions and take corrective actions now Troubleshoot faster and improve end-user experience. Signup Now! http://pubads.g.doubleclick.net/gampad/clk?id=272487151&iu=/4140 _______________________________________________ IPCop-user mailing list [email protected] Manage your subscription or unsubscribe https://lists.sourceforge.net/lists/listinfo/ipcop-user