- Jun 18, 2001
- 105
- 0
- 0
Hey Everyone,
I'm exploring options for putting up and effective firewall and had a couple of questions. Here's the setup: right now, nothing special. I've got a LAN with about 5 PCs, including a Windows domain controller. After graduation (soon), I'll be moving off the compus network and onto wonderful, unfirewalled DSL, where I plan to expand the network to provide outside services such a mail, www hosting, ftp, SSH, possibly DNS, etc. One particular service I'd provide is VPN access for myself to the internal network. I'm counting on only having 1 IP address and using private network addresses for the internal network. Not sure of this yet, but may want to run a DMZ for the main outside servers.
Here's a rundown of the requirements:
- Firewall that keeps out everything but what I want to let in
- Protects an entire Class C network (private IPs)
- VPN access to network (I would guess no more than 1 user at a time)
- VPN able to be connected to via Windows networking...nothing special needed
- Easy to use routing/filtering options
- Can NAT one-to-many (ex. having web servers on different boxes...forward port 80 to all of them)
I think at this point it's safe to say that I'll be wanting more than just a Linksys or Dlink. What I'm curious about is which would be better...getting a dedicated firewall appliance or throwing some open-source firewall onto an old box?
Recently I've been playing with Astaro security linux. It definatley has the advanced options I'd like, as well as the ease of use. I've even got a VPN connection set up with a buddy's network so it's transparent to the my computer to get to one of his. However it's weaknesses lie in the fact that according to the free home-user license, it only protects 10 IPs. And also, I have yet to get the IPSec VPN to work without an external (and pricey) client.
I've looked at Clarkconnect, which doesn't have the IPSec VPN in it's free form. I've also looked at Cisco and SonicWall appliances.
Anyone have opions on what would work good for this?
Thanx,
Jazzman
I'm exploring options for putting up and effective firewall and had a couple of questions. Here's the setup: right now, nothing special. I've got a LAN with about 5 PCs, including a Windows domain controller. After graduation (soon), I'll be moving off the compus network and onto wonderful, unfirewalled DSL, where I plan to expand the network to provide outside services such a mail, www hosting, ftp, SSH, possibly DNS, etc. One particular service I'd provide is VPN access for myself to the internal network. I'm counting on only having 1 IP address and using private network addresses for the internal network. Not sure of this yet, but may want to run a DMZ for the main outside servers.
Here's a rundown of the requirements:
- Firewall that keeps out everything but what I want to let in
- Protects an entire Class C network (private IPs)
- VPN access to network (I would guess no more than 1 user at a time)
- VPN able to be connected to via Windows networking...nothing special needed
- Easy to use routing/filtering options
- Can NAT one-to-many (ex. having web servers on different boxes...forward port 80 to all of them)
I think at this point it's safe to say that I'll be wanting more than just a Linksys or Dlink. What I'm curious about is which would be better...getting a dedicated firewall appliance or throwing some open-source firewall onto an old box?
Recently I've been playing with Astaro security linux. It definatley has the advanced options I'd like, as well as the ease of use. I've even got a VPN connection set up with a buddy's network so it's transparent to the my computer to get to one of his. However it's weaknesses lie in the fact that according to the free home-user license, it only protects 10 IPs. And also, I have yet to get the IPSec VPN to work without an external (and pricey) client.
I've looked at Clarkconnect, which doesn't have the IPSec VPN in it's free form. I've also looked at Cisco and SonicWall appliances.
Anyone have opions on what would work good for this?
Thanx,
Jazzman