OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: [suse-security] Network structure and security

From: Philippe Vogel (filiaapfreenet.de)
Date: Fri Jul 11 2003 - 11:03:09 CDT


I forgot to post some stuff in the last mail:

The firewall depends on the securitiy the machine has from internal.

So you have to build a secure distribution, like debian or gentoo linux or
manipulate SuSE linux that it is secure (minial installation +secumod
+compardment +security level setup +services you need).

If time is money here are some firewall solutions that you can install in
~1/2 hour:

SuSEfirewall on CD

http://www.suse.de/de/business/products/suse_business/firewall/index.html

transtec firewall hardware

http://www.suse.de/de/business/products/suse_business/firewall_hardware/index.html

Astaro Security linux / Mailserver, firewall, proxy, virus protected
content, each module costs a bit :-(

www.astaro.com

The last one I tested and I was impressed of the features
(intrusiondetection, live logview, portscan checks, proxy, webconfiguration,
rulesets ...).
The config can be copied to a disk.
If your server gets intruded you format the disk, reinstall it and copy your
configuration back.
The webinterface is very intuitive and userfriendly, but you must have
knownledge of iptables and rulesets.

Philippe

--
Check the headers for your unsubscription address
For additional commands, e-mail: suse-security-helpsuse.com
Security-related bug reports go to securitysuse.de, not here