J_Worth Posted February 20, 2014 Posted February 20, 2014 (edited) Hello everyone, Just a question: what would you recommend to use as an open source Firewall appliance? I have been looking at Smoothwall Express and IPCop. A firewall appliance with fairly intuitive web based management is pretty much a must. Many thanks. J_Worth. Edited February 20, 2014 by ZeroHour
computer_expert Posted February 20, 2014 Posted February 20, 2014 I moved from smoothwall express to pfSense (at home). the pfSense community seems more active too as I haven't seen a new smoothwall express version for years (and it does feel dated to me when compared against pfSense)
FN-GM Posted February 20, 2014 Posted February 20, 2014 One time i would have said Smoothwall Express, but now i would say PFsense. Smoothwall Express seems dead in the water, personally im disappointed with that
Gaz Posted February 20, 2014 Posted February 20, 2014 I read the title of this thread and thought to myself "thats gotta be pfsense" I opened the thread and looked at the replies...
pantscat Posted February 20, 2014 Posted February 20, 2014 Sorry to barge in as such - but would anyone really use this as an edge firewall? Just curious... and a little bit snobby about open source stuff!
Gaz Posted February 20, 2014 Posted February 20, 2014 Sorry to barge in as such - but would anyone really use this as an edge firewall? Just curious... and a little bit snobby about open source stuff! A lot of commercial firewalls are based on OSS so why not? If you're paranoid and know what you're doing you can get the source files and look through them and see for yourself how robust it is. 1
cpjitservices Posted February 20, 2014 Posted February 20, 2014 Well I think I'd be wasting my time in giving you my opinion - Since I run pfsense all over my network in different buildings, on point to points etc .. .I think you'd know what I'd choose !!
cpjitservices Posted February 20, 2014 Posted February 20, 2014 A lot of commercial firewalls are based on OSS so why not? If you're paranoid and know what you're doing you can get the source files and look through them and see for yourself how robust it is. It's a proven fact that pfsense, is almost unbreakable to hackers not 100% but then no firewall is... there are videos on Defcon showing how good pfsense really is. I use it on a major ISP network for VPN and Firewall and never had a compromise yet. Running steadily for 2 years +. I've also implemented it at Cafe's etc for wifi connectivity using captive portal. Brilliant free piece of awesomeness. - it's build on BSD too so it's definitely solid!
cpjitservices Posted February 20, 2014 Posted February 20, 2014 Just look at this video: Defcon 18 - How to Hack Millions of Routers - YouTube 1
J_Worth Posted February 20, 2014 Author Posted February 20, 2014 Thanks for all the replies - I will give pfSense a go!
FN-GM Posted February 20, 2014 Posted February 20, 2014 @cpjitservices is spot on. None are 100%. Its also recommended you have 2 firewalls anyway, preferably by 2 vendors so if one has a weakness the other can compensate. Our system is protected by both Cisco ASA and Smoothwall.
J_Worth Posted February 20, 2014 Author Posted February 20, 2014 Our internet connection is provided by our LEA so this would technically be a second firewall. Our main reason for this, is so we can VLAN the network and not be limited to the IP range that our LEA have provided us with.
mikeyd101 Posted February 20, 2014 Posted February 20, 2014 Just to be different linux and iptables, ok it lacks a intuitive gui tho I believe you can get a gui app to manage it and it has been around ages meaning loads of documentation. I used to use it on my home server. I heard something that there's a newer linux firewall with slightly better, easier configuration. NFtables.
cpjitservices Posted February 28, 2014 Posted February 28, 2014 PFsense basically is built on PFTables.. from BSD. One of the most stable secure firewall platforms, configured correctly you'd be very secure. PF: Tables
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now