On Sat, Jun 17, 2000 at 06:12:12PM +1000, Dave Kempe wrote:
> Hey Sluggers,
>
> There seems to be many questions about ipchains on this list, and on others
> I lurk on, is there any ratified configuration? Like has anyone said well
> this config is secure, this isn't, or any pointers about actual security of
> ipchains? Most people want to be able to bend ipchains to allow a specific
> service thru or handle a unique combo of services.
Thus the customisation precludes identifying a "secure" configuration of
any sort. There are some good practices to follow (`deny everything' being
one) but unless your network is trivial (e.g. masquarading through a dialup)
it is hard to say.
> I need to be able to sell ipchains on its security vs other
> firewalls/firewall products. What are its advantages/disadvantages over
Possibly your first sentence is why very few, if any, people responded?
You can quote me as saying "I've been running Linux based firewalls
for over 5 years continuously. In that time I've never had an intrusion,
or fault, with Linux"
> other firewalls on any platform? Or to ask a very very open question, is it
> enough security? Enough to withstand what over what? Like some firewalls can
Security isn't a product it is a process. If you are attempting to tell
people that they are/will be secure by installing a product you
recommend you are doing them a disservice.
> resist DoS attacks, others can't etc. Is there a product that combines with
> ipchains to harden it further? Is ipchains considered a "real" firewall? Can
I know of a couple of modifications to ipchains not in the mainstream kernel;
mainly rewrites of the network code in hand-tuned assembler. The author
claims it to be faster than the current networking stack but I have never
tested it myself.
> i sell it as such? Has anyone had any experiences of ipchains vs other
> firewalls and seen which is better?
You are trying to sell ipchains or are you trying to sell a security solution.
I don't think it is valuable to focus on the specifics of the technology, as
that will change, but its purpose.
A lot of commercial shops seem to use Firewall-1; I'm not aware of any
comparisions though. Nor have I searched any out.
> I'm not a salesperson, just you have to sell if you want people to buy your
> services. It seems to me that ipchains is enough security, perhaps combined
> with portsentry if you want tighter security. I guess I just want some more
> confidence in it as a firewall product.
I recommend you buy "Firewalls and Internet Security" by Cheswick and
Bellovin. Chapter 3 will give you the definitions you need if you are
doing technical sales pitches.
Anand
--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text