Easily configurable firewall?
From: Don Felgar (dfelgar@rainierinternet.com)Date: 12/06/01
- Previous message: Dr Anish.M: "RE: buffer overflow question"
- Next in thread: John S. Jacob: "Re: Easily configurable firewall?"
- Reply: John S. Jacob: "Re: Easily configurable firewall?"
- Reply: Brian Cervenka: "Re: FW: Easily configurable firewall?"
- Reply: Michel Blanc: "Re: Easily configurable firewall?"
- Reply: Sebastian Ip: "Re: Easily configurable firewall?"
- Reply: Scott Gifford: "Re: Easily configurable firewall?"
- Reply: Rob Cessac: "Re: Easily configurable firewall?"
- Reply: J C Lawrence: "Re: Easily configurable firewall?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Thu, 6 Dec 2001 01:41:23 -0800 To: focus-linux@securityfocus.com From: Don Felgar <dfelgar@rainierinternet.com>
Hello all,
By way of background: I need to set up seven firewall/VPN/NAT linux
boxes now for some small branch offices, and several more down the
road.
I initially looked into hardware devices, but VPN hardware is
expensive, and there are incompatibilities between different
implementations. (Some of the inexpensive firewall/NAT devices that
"support VPN" actually support "VPN passthrough", which is quite a bit
different.)
My inclination is to avoid the administrative overhead of one VPN
connection between each workstation (windows) and the VPN server, but
rather to VPN once between each branch office and the VPN server. To
do this, I'll assign each branch office a subnet in 192.168.1,
192.168.1.2, etc so they mesh together in the main office.
Yes, I know that a firewall would not serve as a VPN device in an
ideal world. I'm working under a tight hardware budget and don't have
any better ideas.
Anyway, my question is actually this: what's the best way to configure
a group of Linux boxes en masse? My current thinking is that I'll
copy all the .debs (I'm using Debian) that I want onto a cdrom, and
then run a script on each machine that prompts for the bits of
information that differ from one machine to the next, such as IP
addresses, VPN config, etc, and writes them in the appropriate file.
Any better ideas?
TIA
-Don
- Previous message: Dr Anish.M: "RE: buffer overflow question"
- Next in thread: John S. Jacob: "Re: Easily configurable firewall?"
- Reply: John S. Jacob: "Re: Easily configurable firewall?"
- Reply: Brian Cervenka: "Re: FW: Easily configurable firewall?"
- Reply: Michel Blanc: "Re: Easily configurable firewall?"
- Reply: Sebastian Ip: "Re: Easily configurable firewall?"
- Reply: Scott Gifford: "Re: Easily configurable firewall?"
- Reply: Rob Cessac: "Re: Easily configurable firewall?"
- Reply: J C Lawrence: "Re: Easily configurable firewall?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|
|