[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: not using debian as firewall!



Well, the problem with using ANY UNIX type system for a firewall is that it
allows for remote logins.  Now, a truely secure firewall won't allow for remote
logins, which means to disable most features on a system(telnet, ftp, etc...).
It's easy to make it secure, but most people wouldn't secure the box, so
*shrug*.  It's their choice if they want to sacrifice security and allow
services to be run on the box except for the very basic ones.

						Dave Bristel


On Tue, 13 Apr 1999, Matt Kern wrote:

> Date: Tue, 13 Apr 1999 02:49:18 +0100 (GMT)
> From: Matt Kern <mwk20@cam.ac.uk>
> Reply-To: Matt Kern <Matt.Kern@pobox.com>
> To: Debian Devel <debian-devel@lists.debian.org>
> Subject: Re: not using debian as firewall!
> Resent-Date: 13 Apr 1999 01:49:21 -0000
> Resent-From: debian-devel@lists.debian.org
> Resent-cc: recipient list not shown: ;
> 
> On Tue, 13 Apr 1999, Martin Held wrote:
> 
> > On Mon, 12 Apr 1999, Pall Magnusson wrote:
> > 
> > > hey...someone told me a while ago, that you shouldn't use Debian for a
> > > firewall?...why is that?..or is that just crap? :)
> 
> Sounds like one of the many people that has a grudge against GNU/Linux and
> Debian on the principle that it is free and can't be as good as all those
> really expensive boxes you can buy to do basically the same job.
> 
> > Pure crap, IMHO.  I've set up 2 firewalls and IP Masquerading boxes
> > myslef, and I have seen many others.  I'm sitting behind one of them right
> > now. I've found Debian to be better than any of the other distros for a
> > firewall.  (Of course, I'm really not a RedHat guy myself.) 
> 
> I don't think Debian is any better for firewalling per se, however I know
> I would prefer to install it on the grounds that it is easy to use and
> maintain and if there prove to be bugs in any of the networking daemons
> running on the firewall they will probably be fixed soon and upgraded the
> next time I do a routine system check.
> 
> Matt
> 
>   \\\\/////  Matt Kern            Tel: (01223) 366290
>   |       |  Matt.Kern@pobox.com  http://xanadu.pet.cam.ac.uk/~mwk20/
>   | O   O |
>   |   L   |  If I had better tools, I could more effectively
>   | \__   |  demonstrate my total incompetence.
>    \_____/
> 
> 
> 
> -- 
> To UNSUBSCRIBE, email to debian-devel-request@lists.debian.org
> with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
> 


Reply to: