Re: Damn it, ipcop appears dead to me

David W Studeman <[email protected]>
Newsgroups gmane.comp.security.ipcop.user
Message-ID <[email protected]>
Ranbir wrote:

> Hi Everyone,
> 
> I don't see much of any development happening on this project. Maybe
> someone is mashing away at a keyboard somewhere, but it's certainly not
> making its way back to the project.
> 
> I really didn't want to look for another firewall distro. IPCop has
> been great. But, I'm getting nervous with the lack of anything
> happening. This is is supposed to secure my network, but the project
> isn't moving and that's bad!
> 
> I'm not sure yet which one I'm going to move to. The biggest problem
> isn't choosing the right one, but moving my configuration to the new
> system. It's going to suck, that's for sure.
> 
> It's been a great 10+ years, IPCop. I'm sad to go. :(
> 
> Ranbir
> 
> p.s.
> 
> I'll run back if the development pace picks up again and stays active.
> But, I'm not holding my breath.
> 

Well, there haven't been a ton of commits lately but it does not make it 
dead. I'm running a few recent SVN builds and what has happened is that 
IPCop renders perfectly on webkit based browsers now where as it hadn't for 
years.

One of the things that turn me off to the others is the crippled versions 
for the community unless you pay them to unlock things. The only other 
firewall distro I have my eye on and test is OPNsense. It forked from 
PFsense after Netgate bought PFsense. Opnsense's main developer has been 
responsive to the community as far as input. Since the BSD kernel has 
support for TMPFS these days I talked him into using it for flash installs 
versus the old BSD ramdisk filesystem. Hint: TMPFS needs no formatting and 
can be resized on the fly with no data dropping from ram. 

The only thing that concerns me is whether BSD and PFtables can handle sip 
NAT tracking as well as Linux and the now enabled by default in IPCop 
module, nf_conntrack_sip which can have parameters added to provide 
unfettered sip performance with no one way audio or incoming calls not 
reaching you yet still full NAT protection. Forwarding sip ports as others 
suggest to alleviate this is the wrong way to handle this.

Dave Studeman


------------------------------------------------------------------------------
Developer Access Program for Intel Xeon Phi Processors
Access to Intel Xeon Phi processor-based developer platforms.
With one year of Intel Parallel Studio XE.
Training and support from Colfax.
Order your platform today. http://sdm.link/xeonphi
_______________________________________________
IPCop-user mailing list
[email protected]
Manage your subscription or unsubscribe
https://lists.sourceforge.net/lists/listinfo/ipcop-user
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.