[wplug] networking security

Bryce Lynch bryce at telerama.lm.com
Sun Apr 29 13:10:53 EDT 2001


On Sun, 29 Apr 2001, Brad Hoover wrote:

> I thought I would just buy the modem and a hub and
> that would be that.  But I started thinking about the
> security aspects of the setup.  Should I get a router
> instead of the hub, to facilitate a firewall?  Because

You might want to set up a firewall just behind the DOCSIS and hang the
hub/switch off of the internal interface (@home won't let you put multiple
routable IPs on the same cable modem unless you pay for all of them),
using IPmasq to handle connectivity.

> I don't think only a software-based firewall will
> work, particularly if it's windows based.

I've had a great deal of success with FloppyFW
(http://www.zelow.no/floppyfw/) for just this sort of setup.  An insanely
underpowered and underequipped system will work perfectly as a firewall
(lain is only a motherboard, powersupply, two NICs, and a floppy drive
rattling around inside a case - you don't need much to put one together.)

---------------------------------------------------------------------------
-><-   Doctor Who -- KSV bani PLI -- finger for PGP/GnuPG public keys  -><-
Solution: A more subtle problem.
---------------------------------------------------------------------------
		  'doko ni datte, hito wa tsunagatte iru.'




More information about the wplug mailing list