What is the best approach to adopt for firewalls, when planning to install one at organisation ? What would be the preferable destro ?? :) :)
For some time we 've been planing to install one at our organization .. but came to indecision on certainaspect.. as to what should be our approach . For a small/ mid level 100 % netbased business organization where every body is at net on every moment and download : upload ratio is 60:40 and a few solitery server like ( mail server etc).. what 'd be right way to keep out the blues of net.. the big baddies out .
Please guide in this aspect. Although i 've been using Linux for past couple of years and has little mastery on it .. , has yet to come to some firm decision .
Asking for a guide or path showing ..
firewall
i would recommend a hardware-based firewall, but then again, you might have a machine to spare, so why not just setup iptables to block everything unrelated, and forward the ports you want to the servers. not hard at all.. that would be the first step. the distribution hardly matters, but a stripped down version might be preferrable for additional security etc.. there's tons of material out there, and freely available distros that do these kind of things. :)
Okey-doke..
..but there is not, and it has been repeated incessantly,
without fail, for a __very__ long time, and never and never has
been a thing concluded , finished and done as the HARDWARE
firewall. All require an IOS, all require code no matter the
quality, source,destination, etc..
This horrible myth and lack of education needs to stop, and
no better time or place than now.
Yeah, replying to a year old
Yeah, replying to a year old request. The 'best' solution is always the one that works for you. But I'd recommend looking at the SmoothWall Linux distribution. You can turn some spare PC hardware into a dedicated firewall that is easy to setup, manage and upgrade. And secure of course.
.cp