Re: Fw: Debian as My home firewall/router

David W Studeman <[email protected]>
Newsgroups gmane.comp.security.ipcop.user
Message-ID <[email protected]>
On Sat, 27 Feb 2016 16:33:38 -0300, Renaud (Ron) OLGIATI wrote:

> In reply to a query about configuring Debian as a firewall, I suggested
> using IPCop instead.
> 
> This provoked the heated reply I am forwarding below.
> 
> Would any IPCop guru care to comment ?
> 
> Cheers,
>  
> Ron.
> 
> 
> Begin forwarded message:
> 
>  Reco <[email protected]> wrote:
> 
>> > I know that is possible to build a firewall using Debian.
>  
>> It is possible, but why go to the bother when you have dedicated
>> distributions like IPCop that come ready to go, and are by design more
>> secure than a specially-configured Debian will be.
> 
> Please. "Out-of-the-box" IPCop (version 2.1.8 I just grabbed from the
> Sourceforge) does have:
> 
> 1) No meaningful DNSSEC capability.
> 
> 2) Presence of libfontconfig.so *and* fonts for no good reason.
> 
> 3) Bunch of questionable quality root-owner SUID binaries in
> /usr/local/bin, intended to be called from Web-interface.
> 
> 4) Lack of any pre-installed IDS.
> 
> 5) Outdated kernel 3.4, configured *without* SELinux, Apparmor or tomoyo
> support.
> 
> 
> Oh, did I mention that *primary* download mirror for this distribution
> is the Sourceforge?
> 
> IPCop can be an interesting solution for a host on an internal network,
> which nobody intends to poke, but suggesting putting *this* to serve as
> a firewall from an Internet is a joke.
> 
> Reco
> 
> 


He lost me at SELinux and similar programs. Those are aimed at multiple 
users logged into a machine and controlling access as to which user can 
execute, read, or what to which process. SELinux, APParmour and the like 
have always seemed like solutions looking for a problem in the decade plus 
they have been here. While I swear by Debian as a server OS, as a MythTV 
appliance base (uses third party repos) and even as a decent laptop OS, 
Workstation OS etc, I prefer a dedicated, hardened, specific, non bloated 
tiny OS for firewall/routing that was developed to only run as a dedicated 
firewall appliance. He may be doing Debian a disservice with his noisy 
negativist rant. 

IDS, well, I have yet to see a decent one in Linux. When IPCop had it it 
was the most misunderstood and misused feature it had plus it would eat up 
over 100MB of ram per monitored interface, give mostly false positives 
caused by bogus rules and then some of those bogus rules would be removed 
on the next rules update, new rules added and then some of those new rules 
would end up being bogus and throwing false positives. This cycle runs 
from from here to eternity.

To those considering PFsense, I recommend looking at Opnsense which forked 
from PFsense when Netgate bought PFsense and closed down much of the 
access to the code. Pfsense was a fork of Monowall. The author of Monowall 
endorsed Opnsense as the worthy successor and discontinued Monowall as 
having served it's purpose. 

Dave Studeman
http://www.raqcop.com


------------------------------------------------------------------------------
_______________________________________________
IPCop-user mailing list
[email protected]
Manage your subscription or unsubscribe
https://lists.sourceforge.net/lists/listinfo/ipcop-user
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.