Last week, I performed installation and configuration of Shorewall on Fedora Core 6. I made a host-based firewall and some people called it a one-interface firewall. No difficulties encountered and the documentation gave sufficient details for me to understand.
I try to compare FC6's default installed iptable-based firewall functions with Shorewall. For stateful packet inspection of incoming packets, both are more or less the same. However, Shorewall offers additional functions of whitelists, blacklists and limiting the rates of incoming packets. There is no doubt that Shorewall is a perfect choice for people who find it difficult to learn and write some iptables scripts.
This is Warren Kwok's Internet note pad, electronic diary, online rubbish journal, whatever you might name it ! It is an archive of my random thoughts in a chronological order. I am not good at reporting boring things and change them to lively. If you find this blog boring, sorry that it is your problem.
Showing posts with label Firewall. Show all posts
Showing posts with label Firewall. Show all posts
2007/07/15
2007/02/07
A story about firewall
This is a true story.
A large corporation in Hong Kong is using Checkpoint Firewall on Windows 2000 Server as a software firewall. My first thinking is that Windows 2000 Server is not a hardened server OS. How could one rely on a non-hardened server OS to build a mission critical application on top of it. The second thinking I have is that patches for Windows OS are released as frequent as several times a month. When patches are added, the server has to be stopped and re-started. Testing would be followed to check if the added patches will create new problem. The third bad thing is that Windows Server requires periodic reboot, unlike Unix or Linux which do not require re-boot after running for two to three years. This results in some loss of availability. Having said that, I could not imagine how this application can offer 24 x 7 x 365 non-stop service.
A large corporation in Hong Kong is using Checkpoint Firewall on Windows 2000 Server as a software firewall. My first thinking is that Windows 2000 Server is not a hardened server OS. How could one rely on a non-hardened server OS to build a mission critical application on top of it. The second thinking I have is that patches for Windows OS are released as frequent as several times a month. When patches are added, the server has to be stopped and re-started. Testing would be followed to check if the added patches will create new problem. The third bad thing is that Windows Server requires periodic reboot, unlike Unix or Linux which do not require re-boot after running for two to three years. This results in some loss of availability. Having said that, I could not imagine how this application can offer 24 x 7 x 365 non-stop service.
Subscribe to:
Posts (Atom)