Re: "Debian as My home firewall/router" on the debian-user mailing list

Matt James <[email protected]>
Newsgroups gmane.comp.security.ipcop.user
Message-ID <CAAiWk=U85OPZC88ucNOZqpAYS0YFGgcbdKSJyyy7q_QMCsmmrA@mail.gmail.com>
I usually explain it to people like this:

With any security device / product, there is a trade off between usability
and security.  IE: The most secure devices are often also the most
difficult to use / present the most hurdles.

So, one has to ask - what's the risk?  What is your acceptable level of
risk?  What do you stand to lose?

When you think about your house - you lock your doors, right?  And probably
your windows, and keep the garage shut, etc.  Now, will that keep out
someone who is intent on breaking into your house out?  No, of course not.
So, for some folks, having doors and windows that lock isn't acceptable
enough for their security, so they purchase an alarm system, maybe get a
dog, or buy a gun.  But still, will this stop someone who is _really_
intent on getting into your house?  Still, no.  So to take it to the next
level, you move 200 miles from anyone, you put 20' concrete walls around
your house, hire armed guards, and insist on DOD level background checks
before anyone can enter your home.  Now - THAT is a pain in the @$$ but
also affords you considerably less risk than simply locking the door and
closing the garage.

Similarly, with firewalls, most people change the default password on their
wifi, lock down unused ports on their firewall, and keep anti-virus up to
date, etc.  For those that want a little extra - they use something like
IPcop / pfsense / or SOHO routers (think Sonicwall, EdgeRouter Lite, etc.)
 But for those who just HAVE to have the 20' walls, they roll their own
highly customized solution or spend several hundreds of thousands of
dollars (if not more) on purpose built commercial hardware solutions (think
Palo Alto, Cisco, Juniper, etc.)

So - back to the question, what do you have to protect? and What is your
acceptable level of risk?

For me and my lowly home network, IPcop is sufficient.  For most of my
customers, IPcop is sufficient.  But is it sufficient for fortune 500
companies?  Not even close. And those in between?  Well, that's up for
debate.  :-)

My $0.02

Matt

On Sun, Feb 28, 2016 at 10:28 AM, David Christensen <
dpchrist-xyI/[email protected]> wrote:

> On 02/28/2016 06:23 AM, Administrator wrote:
> >
> > On Saturday 27 Feb 2016 11:20:49 David Christensen wrote:
> >
> >> ipcop-user:
> >>
> >> There is a thread "Debian as My home firewall/router" on the debian-user
> >> mailing list.  One poster mentioned IPCop as a possible solution, but
> >> another has claimed that there are significant flaws in IPCop.  I used
> >> IPCop for many years, and found it to be very useful.  I am curious if
> >> the criticism is accurate.
> >>
> >>
> >> It would be helpful if a person knowledgeable in the IPCop project and
> >> IPCop internals joined the discussion:
> >>
> >>       https://lists.debian.org/debian-user/
> >>
> >>       https://lists.debian.org/debian-user/2016/02/msg00963.html
> >>
> >>
> >> David
> >
> > My view on this is different as I'm knowledgeable but not an expert.  I
> have 4
> > choices: use a retail gateway / firewall device; use IPCop / pfsense or
> > something similar; use a professional gateway / firewall device;
> hand-roll my
> > own on top of a trusted distribution.
> >
> > Retail devices are repeatedly reported for security flaws which remain
> un-
> > patched for months.  That's a fail.
> >
> > Professional devices are better, but expensive and complex to set up
> securely.
> > Hand-rolled gateway / firewall on top of a generic distribution is even
> more
> > complex to set up securely and maintain.  I don't have the time for
> either.
> >
> > Complexity is a security risk, as is the need for perpetual learning to
> keep
> > up-to-date on the latest threats and best practice.
> >
> > That leaves IPCop / pfsense ... they strike a good balance between
> security
> > and complexity, with the cost being acceptable :-)
> >
> > YMMV
> > David
>
> I did a similar calculation and came up with a similar result.
>
>
> I'm currently using a residential gateway provided by AT&T U-verse.  The
> first died within 24 hours.  The second has been up for months without
> reboot, and seems to be fast and have strong radios.  But, the feature
> set is small, I have no idea of the quality of security, and I have no
> idea if it has been updating/ patching itself (I certainly have not
> updated it).
>
>
> But, none of the above addresses the IPCop-specific issues raised on the
> debian-user mailing list.  They would be most properly addressed on that
> list; please see the URL's I posted, above.
>
>
> David
>
>
>
> ------------------------------------------------------------------------------
> Site24x7 APM Insight: Get Deep Visibility into Application Performance
> APM + Mobile APM + RUM: Monitor 3 App instances at just $35/Month
> Monitor end-to-end web transactions and take corrective actions now
> Troubleshoot faster and improve end-user experience. Signup Now!
> http://pubads.g.doubleclick.net/gampad/clk?id=272487151&iu=/4140
> _______________________________________________
> IPCop-user mailing list
> [email protected]
> Manage your subscription or unsubscribe
> https://lists.sourceforge.net/lists/listinfo/ipcop-user
>
------------------------------------------------------------------------------
Site24x7 APM Insight: Get Deep Visibility into Application Performance
APM + Mobile APM + RUM: Monitor 3 App instances at just $35/Month
Monitor end-to-end web transactions and take corrective actions now
Troubleshoot faster and improve end-user experience. Signup Now!
http://pubads.g.doubleclick.net/gampad/clk?id=272487151&iu=/4140
_______________________________________________
IPCop-user mailing list
[email protected]
Manage your subscription or unsubscribe
https://lists.sourceforge.net/lists/listinfo/ipcop-user
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.