Re: setting up a minimal PC as RH9 firewall

From: Andy (andyfr-at-datacom-dot-co-dot-nz)
Date: 10/22/03


Date: Thu, 23 Oct 2003 09:34:47 +1300


€®ik wrote:
> I want to set up a minimal PC (as in power consumption) as a RH9
> firewall.
> I was thinking of getting an old 486 board, with no fans, no harddisk
> and maybe get the thing booted from floppy and/or CDROM.
> I'd make the CD on another machine...
>
> Or maybe get it to boot from the NIC card, getting the OS from a
> machine in the local network.
>
> I would want to build the minimal kernel myself, or get a really good
> one from the net somewhere.
> I want to build the Netfilter / IPTables myself, using one or two good
> books on Netfilter.
>
> So, lots of problems to solve, lots to learn in the process.
>
> Anyone have suggestions on where to find relevant info and software ?
> I already have RH9 and I can build a kernel.
> Main thing is getting the stuff on CD and bootfloppy: what goes where
> and how.
> Most old 486 boards can't boot from CD, can they ?
>
> frgr
> Erik
>

RH9 may me a bit over the top for this by the time you strip the kernel
back.

Have a look at http://www.zelow.no/floppyfw/ for yet another "ready to
roll" linux/iptables firewall that will boot from a floppy and has
minimal hardware requirements.

- Andy -



Relevant Pages

  • Re: About security...
    ... services listening on the network interface - there are some listening ... off-chance that such a kernel flaw is discovered. ... you enable netfilter code in kernel - this is what you do when you use ... It will not be exposed unless you go and change your firewall config. ...
    (Ubuntu)
  • Re: Upgrade from RH9 to FC3 or FC4
    ... > I have an old machine running as a firewall. ... It's basically an RH9 ... the introduction of FC3 and the 2.6 kernel. ... It's becoming increasingly difficult to install Fedora or any other major ...
    (Fedora)
  • Re: Highly OT, but the partys over
    ... Security is inherent but a firewall is not part of the kernel. ... iptables configuration programme, of which there are plenty, myself I ... Netfilter on the other hand does, ...
    (rec.autos.sport.f1)
  • Re: natd starting after firewall rules are loaded
    ... that I did, in fact, build the kernel with several firewall options, ... kernel and built it, and, since divert is already there, the firewall ... Once the system is up, i can ipfw list and the divert command is, ...
    (freebsd-net)
  • [patch] move ipfw logging to after syslogd
    ... We have a problem that on our busy firewalls, a boot and shutdown ... can be delayed by up to 20 minutes by the kernel printing log ... most kernel activity appears to be suspended by outputting ipfw ... echo 'Firewall rules loaded.' ...
    (freebsd-current)