Web Server Security : Dedicated firewall

by Sharen Scott on October 19, 2009

The first firewall that’s going to be presented here is SmoothWall. Probably the best description for SmoothWall is that it is undoubtedly one of the most user-friendly firewall suites that can be found as open source. It’s totally configurable via a web-based GUI. It’s based on Linux but requires very little *nix knowledge. Anyone that can set up a working Linux installation should not struggle working with this firewall.

The company that maintains this project is based in the UK, and they have a great history to back up their expertise. The SmoothWall project was launched in the early 2000s. Right now there are several variations of this project. These include SmoothWall Express, which is the free open source edition, and a few commercial products such as the Corporate Guardian, Corporate Server Edition, Network Guardian, etc.

In this article we’re interested in SmoothWall Express. Its latest version is 3.0, codenamed Polar. Let’s enumerate some of its key features: stateful inspection, dynamic NAT, outgoing traffic control, port forwarding, IP block list, web proxy, VoIP, PPP, PPPoA, PPPoE ADSL support, IPsec VPN, Intrusion Detection System.

Check out this official document—it’s always up to date. It also provides a comparison with their commercial applications, so you can find out their capabilities in comparison with the free SmoothWall Express. You can decide for yourself whether the open source version or one of the others will satisfy your needs.

Another open source firewall application is Endian. Endian provides top of the line UTM (unified threat management) firewall products that also include customer support, but they also offer the Endian UTM Community edition. As its name suggests, the project has matured into a full-featured Internet security and intrusion prevention suite.

The beauty of this project is that it is a mixture of open-source utilities and applications. Endian has configured, prepared, and released this suite under the GPL license. It comes within a highly-secured Linux distribution and it does an amazing job of making things easy for everybody, even users without any background in Linux and/or conventional firewall apps such as iptables/netfilter.

Now let’s also find out its major functions: stateful firewall (packet inspection), proxies for various protocols with antivirus support, DDoS protection, portscan detection, DNS proxy/routing, VOIP support, content filtering of Web traffic, spam-filter (learning) and antivirus for both incoming and outgoing mails, support for VPN based on OpenVPN, and much more! Check out the following comparison of features—here.

The third firewall suite we’ll consider on this page is ClarkConnect. This product is often called an Internet gateway solution because it offers many of the required tools to create a secure network with this robust gateway/firewall suite. It comes in two variations: community (free, open-source), and enterprise (commercial).

The free community edition has the following limitations: at most 10 mailboxes, no technical support, and a maximum of 18 months of automatic software updates. The user may thereafter update the software with manual updates—and this is important for antivirus definitions and other reasons. As expected, ClarkConnect is also based on Linux.

Some of its major features include, but are not limited to: stateful firewall (via the traditional iptables), intrusion detection and prevention system, VPN (via PPTP, OpenVPN, IPsec), web proxy and caching (via Squid), content filtering (DansGuardian), lots of e-mail services (spams, antivirus, blacklisting, webmail), web server (Apache), database (MySQL), file and print services (Samba, CUPS), MultiWAN, and lots of others.

Pages: 1 2 3 4

{ 1613 comments… read them below or add one }

Dvd Writer Software August 4, 2010 at 9:56 pm

Dvd Writer Software
Thanks a lot for the blog post.Much thanks again. Want more.

captain america the first avenger August 4, 2010 at 9:59 pm

http://www.captain-america-the-first-avenger.com
The beginning is the half of every action.

pheromone collar August 5, 2010 at 1:58 am

http://www.pheromonecollar.com
He can cheat a fish of its skin.

Yellow Light Of Death Fix August 5, 2010 at 2:40 am

Yellow Light Of Death Fix
Really informative blog article. Really Great.

Clicker Training August 5, 2010 at 4:05 am

Clicker Training
Muchos Gracias for your blog post.Really looking forward to read more. Much obliged.

androstenone pheromone concentrate August 5, 2010 at 10:51 am

http://www.androstenonepheromoneconcentrate.net
They are like the clue in the labyrinth or the compass in the night.

Nose Irrigating August 5, 2010 at 11:55 am

Nose Irrigating
Enjoyed every bit of your blog.Thanks Again. Really Great.

Arkadelphia Apartments August 5, 2010 at 12:47 pm

Arkadelphia Apartments
Really enjoyed this post.Thanks Again. Awesome.

Todd August 5, 2010 at 3:56 pm

Todd
Thanks a lot for the blog.Thanks Again. Will read on…

send flowers from usa August 5, 2010 at 5:59 pm

http://www.sendflowersfromusa.com
cheers for that, some food for thought.

androstenone pheromone concentrate August 5, 2010 at 6:54 pm

http://www.androstenonepheromoneconcentrate.net
Do what your teacher says but not what he does.

flowers sydney August 5, 2010 at 8:58 pm

http://www.flowerssydney.org
Thanks for your comments… really enjoyed the read. cheers

flowers sydney August 5, 2010 at 9:22 pm

http://www.flowerssydney.org
hmmm… something to definately think about.

Previous post:

Next post: