Re: Easily configurable firewall?

From: Michel Blanc (mblanc@erasme.org)
Date: 12/06/01


Date: Thu, 06 Dec 2001 23:49:03 +0100
From: Michel Blanc <mblanc@erasme.org>
To: Don Felgar <dfelgar@rainierinternet.com>


Don Felgar wrote:

> Hello all,
>
> By way of background: I need to set up seven firewall/VPN/NAT linux
> boxes now for some small branch offices, and several more down the
> road.
>

> Anyway, my question is actually this: what's the best way to configure
> a group of Linux boxes en masse? My current thinking is that I'll
> copy all the .debs (I'm using Debian) that I want onto a cdrom, and
> then run a script on each machine that prompts for the bits of
> information that differ from one machine to the next, such as IP
> addresses, VPN config, etc, and writes them in the appropriate file.
> Any better ideas?

You could use PIKT, which is exactly fitted for that task, with other
neat features (notably lots of system integrity checking thru
programmable checks). It's development is very active, and it's
developpers very responsive.
Management thru PIKT is really powerfull. You can use if/elsif/else in
your config files, use macros, etc... and deploy all your config files
on choosen hosts/hosts groups via a single command line call.

Also, PIKT has been around for years and has been extensively used.
You can get a look at http://pikt.org

Hope it helps,

Michel.

--



Relevant Pages

  • Re: Move /usr/sup to /var/db/sup?
    ... FWIW, I started doing this on boxes I was responsible for a long time ... the config files is /usr/local/etc/, and the proper location for the ...
    (freebsd-arch)
  • Re: Fedora 1 eth0 problem
    ... What config files do you need? ... | I suspect you're just misforming the command in LinNeighborhood, ... GUI for browsing and mounting shares on win boxes. ... or mount shared directory on that box (but smbmount ...
    (comp.os.linux.networking)
  • Re: Deploying sendmail update
    ... update from the sendmail site on one of the boxes OK. ... on eachof the boxes. ... The config files may need changing for each box. ... distro he's running, so one can't suggest anything further. ...
    (comp.os.linux.security)