Re: "Debian as My home firewall/router" on the debian-user mailing list
Matt James <[email protected]>
| Newsgroups | gmane.comp.security.ipcop.user |
|---|---|
| Message-ID | <CAAiWk=U85OPZC88ucNOZqpAYS0YFGgcbdKSJyyy7q_QMCsmmrA@mail.gmail.com> |
I usually explain it to people like this: With any security device / product, there is a trade off between usability and security. IE: The most secure devices are often also the most difficult to use / present the most hurdles. So, one has to ask - what's the risk? What is your acceptable level of risk? What do you stand to lose? When you think about your house - you lock your doors, right? And probably your windows, and keep the garage shut, etc. Now, will that keep out someone who is intent on breaking into your house out? No, of course not. So, for some folks, having doors and windows that lock isn't acceptable enough for their security, so they purchase an alarm system, maybe get a dog, or buy a gun. But still, will this stop someone who is _really_ intent on getting into your house? Still, no. So to take it to the next level, you move 200 miles from anyone, you put 20' concrete walls around your house, hire armed guards, and insist on DOD level background checks before anyone can enter your home. Now - THAT is a pain in the @$$ but also affords you considerably less risk than simply locking the door and closing the garage. Similarly, with firewalls, most people change the default password on their wifi, lock down unused ports on their firewall, and keep anti-virus up to date, etc. For those that want a little extra - they use something like IPcop / pfsense / or SOHO routers (think Sonicwall, EdgeRouter Lite, etc.) But for those who just HAVE to have the 20' walls, they roll their own highly customized solution or spend several hundreds of thousands of dollars (if not more) on purpose built commercial hardware solutions (think Palo Alto, Cisco, Juniper, etc.) So - back to the question, what do you have to protect? and What is your acceptable level of risk? For me and my lowly home network, IPcop is sufficient. For most of my customers, IPcop is sufficient. But is it sufficient for fortune 500 companies? Not even close. And those in between? Well, that's up for debate. :-) My $0.02 Matt On Sun, Feb 28, 2016 at 10:28 AM, David Christensen < dpchrist-xyI/[email protected]> wrote: > On 02/28/2016 06:23 AM, Administrator wrote: > > > > On Saturday 27 Feb 2016 11:20:49 David Christensen wrote: > > > >> ipcop-user: > >> > >> There is a thread "Debian as My home firewall/router" on the debian-user > >> mailing list. One poster mentioned IPCop as a possible solution, but > >> another has claimed that there are significant flaws in IPCop. I used > >> IPCop for many years, and found it to be very useful. I am curious if > >> the criticism is accurate. > >> > >> > >> It would be helpful if a person knowledgeable in the IPCop project and > >> IPCop internals joined the discussion: > >> > >> https://lists.debian.org/debian-user/ > >> > >> https://lists.debian.org/debian-user/2016/02/msg00963.html > >> > >> > >> David > > > > My view on this is different as I'm knowledgeable but not an expert. I > have 4 > > choices: use a retail gateway / firewall device; use IPCop / pfsense or > > something similar; use a professional gateway / firewall device; > hand-roll my > > own on top of a trusted distribution. > > > > Retail devices are repeatedly reported for security flaws which remain > un- > > patched for months. That's a fail. > > > > Professional devices are better, but expensive and complex to set up > securely. > > Hand-rolled gateway / firewall on top of a generic distribution is even > more > > complex to set up securely and maintain. I don't have the time for > either. > > > > Complexity is a security risk, as is the need for perpetual learning to > keep > > up-to-date on the latest threats and best practice. > > > > That leaves IPCop / pfsense ... they strike a good balance between > security > > and complexity, with the cost being acceptable :-) > > > > YMMV > > David > > I did a similar calculation and came up with a similar result. > > > I'm currently using a residential gateway provided by AT&T U-verse. The > first died within 24 hours. The second has been up for months without > reboot, and seems to be fast and have strong radios. But, the feature > set is small, I have no idea of the quality of security, and I have no > idea if it has been updating/ patching itself (I certainly have not > updated it). > > > But, none of the above addresses the IPCop-specific issues raised on the > debian-user mailing list. They would be most properly addressed on that > list; please see the URL's I posted, above. > > > David > > > > ------------------------------------------------------------------------------ > Site24x7 APM Insight: Get Deep Visibility into Application Performance > APM + Mobile APM + RUM: Monitor 3 App instances at just $35/Month > Monitor end-to-end web transactions and take corrective actions now > Troubleshoot faster and improve end-user experience. Signup Now! > http://pubads.g.doubleclick.net/gampad/clk?id=272487151&iu=/4140 > _______________________________________________ > IPCop-user mailing list > [email protected] > Manage your subscription or unsubscribe > https://lists.sourceforge.net/lists/listinfo/ipcop-user > ------------------------------------------------------------------------------ Site24x7 APM Insight: Get Deep Visibility into Application Performance APM + Mobile APM + RUM: Monitor 3 App instances at just $35/Month Monitor end-to-end web transactions and take corrective actions now Troubleshoot faster and improve end-user experience. Signup Now! http://pubads.g.doubleclick.net/gampad/clk?id=272487151&iu=/4140 _______________________________________________ IPCop-user mailing list [email protected] Manage your subscription or unsubscribe https://lists.sourceforge.net/lists/listinfo/ipcop-user