<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ItsyourIP.com &#187; Linux</title>
	<atom:link href="http://www.itsyourip.com/category/Linux/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.itsyourip.com</link>
	<description>Your gateway to Internet</description>
	<lastBuildDate>Sat, 24 Jan 2009 16:48:31 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
<image>
<link>http://www.itsyourip.com</link>
<url>http://www.itsyourip.com/wp-content/mbp-favicon/Internet-Alt.ico</url>
<title>ItsyourIP.com</title>
</image>
		<item>
		<title>WWWOFFLE &#8211; Free Webproxy with privacy Security Offline support</title>
		<link>http://www.itsyourip.com/Linux/wwwoffle-free-webproxy-with-privacy-security-offline-support/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=wwwoffle-free-webproxy-with-privacy-security-offline-support</link>
		<comments>http://www.itsyourip.com/Linux/wwwoffle-free-webproxy-with-privacy-security-offline-support/#comments</comments>
		<pubDate>Sat, 15 Mar 2008 16:14:13 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[proxy]]></category>
		<category><![CDATA[cache]]></category>
		<category><![CDATA[http]]></category>
		<category><![CDATA[HTTPS]]></category>
		<category><![CDATA[SSL]]></category>
		<category><![CDATA[WebProxy]]></category>
		<category><![CDATA[WWWOFFLE]]></category>

		<guid isPermaLink="false">http://www.itsyourip.com/Linux/wwwoffle-free-webproxy-with-privacy-security-offline-support/</guid>
		<description><![CDATA[WWWOFFLE &#8211; World Wide Web Offline Explorer is a free simple easy to configure Webproxy with good security and privacy features. WWWOFFLE is designed to work for Unix and Linux based systems and a partially functional port is available for Windows. WWWOFFLE can be used for a network with multiple PCs or can be used [...]]]></description>
			<content:encoded><![CDATA[<div class="KonaBody"><p><!--adsense#content_336_280-->
<p>WWWOFFLE &#8211; World Wide Web Offline Explorer is a free simple easy to configure Webproxy with good security and privacy features. WWWOFFLE is designed to work for Unix and Linux based systems and a partially functional port is available for Windows.</p>
<p> WWWOFFLE can be used for a network with multiple PCs or can be used just on your local PC to improve performance and offline availability of pages.</p>
<p> <span id="more-167"></span>While WWWOFFLE covers the basic features of a webproxy, there are some special features of WWWOFFLE that is worth mentioning. Especially the Offline access feature specially for Dial-up connections, easy configuration options with a web-interface and the level of control on the caches, index of the caches and security.</p>
<p> Once installed, WWWOFFLE by default listens on the port 8080. There is a detailed list of compatible browser versions <a href="http://www.gedanken.demon.co.uk/wwwoffle/#Compatibility" target="_blank" title="WWWOFFLE - Brower compatibility">here</a>. Worth having a look before implementing the proxy system. Also, the configuration can be fine tuned to the user requirement level.</p>
<p> Some of the highlighting features of WWWOFFLE are<strong><br /> </strong></p>
<blockquote><p> <strong>Easy configuration and a built-in web interface for easy configuration and access to cached contents,certifcates for HTTPS etc.</strong></p>
<p> <strong>Easy administration with autmated start/stop</strong></p>
<p> <strong>Timeout configuration for DNS,Remote Server connections etc to avoid the server crashing</strong></p>
<p> <strong>Download control including Pause &amp; Stop for interrupted downloads</strong></p>
<p> <strong>Purging old cache and control purging action by maximum cache size, time since last access or last caching</strong></p>
<p> <strong>Auto Proxy configuration using Auto-config file</strong></p>
<p> <strong>Conditional fetch of pages that have changed based on Expiration Date, Time since last fetch or Once per session</strong></p>
<p> <strong>Non-Cached Support for SSL Connections</strong></p>
<p> <strong>Caching support for HTTPS connections</strong></p>
<p> <strong>Block access to pages and support redirect to alternate pages (like pages educating users on Internet usage policy or redirect to company homepage)</strong></p>
<p> <strong>Control pages in cache and backup cache for offline use</strong></p>
<p> <strong>Support Compressed pages and Chunked transfer-encoding request from webservers</strong></p>
<p> <strong>Dial-on demand for contents not in cache and control websites that can be downloaded the next time system goes online</strong></p>
<p> <strong>Offline access fine tune by controlling what can be accessed from cache</strong></p>
<p> <strong>Automatic fetching of selected pages and objects from pages and monitoring select pages at regular intervals and recurrsive caching by following links</strong></p>
<p> <strong>Insert Footers and modify HTML pages to remove page objects like scripts, javascripts etc</strong></p>
<p> <strong>Information on cached pages and the index of the cached pages with multiple indexes for cached pages. Also can search the cached pages using various tools.</strong></p>
<p> <strong>Automatic Authentication for external proxies, support pages with username/password for authentication</strong></p>
<p> <strong>Censor incoming and outgoing HTTP headers as to what you reveal about your information like browser type etc. This enhances privacy on the internet</strong></p></blockquote>
<p>For more information, documentation, example scripts to start with and download, <a href="http://www.gedanken.demon.co.uk/wwwoffle/" target="_blank" title="WWWOFFLE - Free web proxy with security,offline and privacy support">click here</a> for WWWOFFLE homepage.</p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.itsyourip.com%2FLinux%2Fwwwoffle-free-webproxy-with-privacy-security-offline-support%2F';
  addthis_title  = 'WWWOFFLE+%26%238211%3B+Free+Webproxy+with+privacy+Security+Offline+support';
  addthis_pub    = '';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
</div><!-- KonaBody -->]]></content:encoded>
			<wfw:commentRss>http://www.itsyourip.com/Linux/wwwoffle-free-webproxy-with-privacy-security-offline-support/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>RANCID &#8211; Network Device Config Differ,Config Change alert,backup</title>
		<link>http://www.itsyourip.com/cisco/rancid-network-device-config-differconfig-change-alertbackup/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=rancid-network-device-config-differconfig-change-alertbackup</link>
		<comments>http://www.itsyourip.com/cisco/rancid-network-device-config-differconfig-change-alertbackup/#comments</comments>
		<pubDate>Wed, 30 Jan 2008 14:54:31 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Cisco]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Network Inventory]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[config-backup]]></category>
		<category><![CDATA[config-change-alert]]></category>
		<category><![CDATA[config-differ]]></category>
		<category><![CDATA[juniper]]></category>
		<category><![CDATA[rancid]]></category>

		<guid isPermaLink="false">http://www.itsyourip.com/cisco/rancid-network-device-config-differconfig-change-alertbackup/</guid>
		<description><![CDATA[RANCID is Really Awesome New Cisco Config Differ. AS its name implies, RANCID monitors network device configuration, including software and hardware and uses CVS (Concurrent Version System) or Subversion to maintain history of changes. RANCID is simple and is easy to use. The same very functionality of RANCID can be used as a backup system [...]]]></description>
			<content:encoded><![CDATA[<div class="KonaBody"><p><!--adsense#content_336_280-->
<p>RANCID is Really Awesome New Cisco Config Differ. AS its name implies, RANCID monitors network device configuration, including software and hardware and uses CVS (Concurrent Version System) or Subversion to maintain history of changes. RANCID is simple and is easy to use.</p>
<p> The same very functionality of RANCID can be used as a backup system for Network device config backup system or even a config change alert system as it can email changes from previous saved configurations. All this RANCID does by logging on to a network device using Telnet or SSH and runs various show commands to grab config changes (hardware &amp; Software), send alert emails of any changes, format the info and commit to the CVS system.</p>
<p><span id="more-145"></span></p>
<p> Some of the devices that RANCID supports</p>
<blockquote><p><strong>Cisco Routers and Cisco Catalyst Switches (IOS &amp; CatOS)</p>
<p> Juniper Routers</p>
<p> Foundry Switches</p>
<p> HP ProCurve Switches</p>
<p> Alteon Switches</p>
<p> Redback NAS</p>
<p> ADC EZT3 MUXs</p>
<p> MRTd &amp; IRRd</strong> </p></blockquote>
<p> RANCID is a Linux based software and needs to be compiled and installed (unfortunately there is no package built for specific Linux platforms)</p>
<p> RANCID can be downloaded from SHURBBERY networks <a href="ftp://ftp.shrubbery.net/pub/rancid/rancid-2.3.1.tar.gz" target="_blank" title="Download RANCID config differ">here </a></p>
<p>RANCID requires the expect module installed on the Linux platform. A sample email notification showing changes based on the previous config versions can be found <a href="http://www.shrubbery.net/rancid/#started" target="_blank" title="Sample email notification from RANCID">here</a>.</p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.itsyourip.com%2Fcisco%2Francid-network-device-config-differconfig-change-alertbackup%2F';
  addthis_title  = 'RANCID+%26%238211%3B+Network+Device+Config+Differ%2CConfig+Change+alert%2Cbackup';
  addthis_pub    = '';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
</div><!-- KonaBody -->]]></content:encoded>
			<wfw:commentRss>http://www.itsyourip.com/cisco/rancid-network-device-config-differconfig-change-alertbackup/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Packet Fence &#8211; Opensource NAC (Network Access Control)</title>
		<link>http://www.itsyourip.com/Security/packet-fence-opensource-nac-network-access-control/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=packet-fence-opensource-nac-network-access-control</link>
		<comments>http://www.itsyourip.com/Security/packet-fence-opensource-nac-network-access-control/#comments</comments>
		<pubDate>Sat, 29 Dec 2007 17:38:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Opensource NAC]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[captive-portal]]></category>
		<category><![CDATA[fingerprinting]]></category>
		<category><![CDATA[nac]]></category>
		<category><![CDATA[nessus]]></category>
		<category><![CDATA[OpenSource]]></category>
		<category><![CDATA[snort]]></category>

		<guid isPermaLink="false">http://www.itsyourip.com/Security/packet-fence-opensource-nac-network-access-control/</guid>
		<description><![CDATA[Packet Fence is an OpenSource NAC (Network Access Control) Solution available under GPL license and is completely free. Packet Fence is a Network Access Control solution with world class features and many features beating those provided by expensive commercial alternatives. Mostly installed in acamedic institutions, please visit here to find a list of organisations and [...]]]></description>
			<content:encoded><![CDATA[<div class="KonaBody"><p><!--adsense#content_336_280-->
<p>Packet Fence is an OpenSource NAC (Network Access Control) Solution available under GPL license and is completely free. Packet Fence is a Network Access Control solution with world class features and many features beating those provided by expensive commercial alternatives. Mostly installed in acamedic institutions, please visit <a href="http://www.packetfence.org/wiki.html" target="_blank" title="Packet Fence used by world class institutions">here</a> to find a list of organisations and institutions that use Packet Fence as a Network Access Control system.</p>
<p><span id="more-132"></span></p>
<p>Packet Fence is built on Redhat/Fedora Linux and can be built from source and installed on most if not on all of the Linux distributions. Packet Fence is easily configurable with a good GUI although installation takes a bit of a hardwork as it involves installing a lot of other opensource software and tools for it to work like <a href="http://www.nessus.org" title="Nessus - Opensource Vulnerability Scanner">Nessus</a> (Opensource Security Vulnerability Scanner) and <a href="http://www.snort.org" title="Snort - Opensource Intrusion Detection and Prevention">Snort</a> (Opensource Intrusion Detection). Packet Fence is now also available as a VMware image (PF ZEN) that can be downloaded from their website. This requires no work (a zero effort installation) and can be operational almost instantly (ideal for testing before deployment).</p>
<p>Highlighting features of Packet Fence include:</p>
<ul>
<li>Operate in INLINE, PASSIVE using ARP Spoofing/Poisoning)&amp; DHCP mode</li>
</ul>
<ul>
<li>VLAN switching support to be available soon (a workaround for VLAN supoort has beed submitted here)</li>
</ul>
<ul>
<li>Registration Mechanism similar to a Captive Portal systems with multiple authentication support (All Apache supported authentications)</li>
</ul>
<ul>
<li>Worm and Virus Detection, alert and Supression (Snort for Detection)</li>
</ul>
<ul>
<li>Worm and Bot detection and Isolation</li>
</ul>
<ul>
<li>Mitigation and Remediation using User-direction for trapped hosts</li>
</ul>
<ul>
<li>Proactive Vulnerability Scans using NESSUS</li>
</ul>
<ul>
<li>DHCP Fingerprinting</li>
</ul>
<ul>
<li>OS Fingerprinting and Banning</li>
</ul>
<ul>
<li>NAC and AP detection and Isolation</li>
</ul>
<p>Good documentation with installation and configuration information available online, Packet Fence is a great Opensource NAC.</p>
<p>Actively developed and supported by the community, packet fence can also offer commercial support on request.</p>
<p>For more information and download, please visit Packet Fence website <a href="http://www.packetfence.org/" target="_blank" title="Packet Fence - Oepnsource NAC">here</a></p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.itsyourip.com%2FSecurity%2Fpacket-fence-opensource-nac-network-access-control%2F';
  addthis_title  = 'Packet+Fence+%26%238211%3B+Opensource+NAC+%28Network+Access+Control%29';
  addthis_pub    = '';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
</div><!-- KonaBody -->]]></content:encoded>
			<wfw:commentRss>http://www.itsyourip.com/Security/packet-fence-opensource-nac-network-access-control/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>How to Disable ICMP Redirects in Linux for security (Redhat,Debian,Ubuntu,SuSe tested)</title>
		<link>http://www.itsyourip.com/Security/how-to-disable-icmp-redirects-in-linux-for-security-redhatdebianubuntususe-tested/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=how-to-disable-icmp-redirects-in-linux-for-security-redhatdebianubuntususe-tested</link>
		<comments>http://www.itsyourip.com/Security/how-to-disable-icmp-redirects-in-linux-for-security-redhatdebianubuntususe-tested/#comments</comments>
		<pubDate>Thu, 13 Dec 2007 19:38:20 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Debian]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Redhat]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Ubuntu]]></category>
		<category><![CDATA[ICMP-redirects]]></category>
		<category><![CDATA[suse]]></category>

		<guid isPermaLink="false">http://www.itsyourip.com/Security/how-to-disable-icmp-redirects-in-linux-for-security-redhatdebianubuntususe-tested/</guid>
		<description><![CDATA[ICMP Redirects Send and Accept are by default enabled on most of the linux flavours including Debian, Ubuntu, Redhat Enterprise Linux, Suse Linux. While ICMP Redirects are not the very efficient way to update a hosts Routing table of an optimal route to a target destination, it can cause serious security concerns where a hacker [...]]]></description>
			<content:encoded><![CDATA[<div class="KonaBody"><p><!--adsense#content_336_280-->
<p>ICMP Redirects Send and Accept are by default enabled on most of the linux flavours including Debian, Ubuntu, Redhat Enterprise Linux, Suse Linux.</p>
<p><span id="more-128"></span></p>
<p>While ICMP Redirects are not the very efficient way to update a hosts Routing table of an optimal route to a target destination, it can cause serious security concerns where a hacker or attacker can send malicously crafted ICMP redirect messages and cause a Denial of Service attack on the network.</p>
<p>If ICMP Redirects are not used in the network for route updates and if the server is not acting as a Router or a Gateway (ICMP Redirect send only) then ICMP Redirect send and accepts should be disabled on the server.</p>
<p>In most of the Linux flavors (tested on Debian,Ubuntu,Redhat Enterprise linux,Suse) ICMP Redirects can be dynamically disabled on the host by using</p>
<p><strong><u><font color="#009900">1. /sbin/sysctl utility which can modify Kernel paramters at runtime</font></u></strong></p>
<p>Login as root and run the following command to disable ICMP Redirects Send and Accept</p>
<p><font color="#009999">Server# /sbin/sysctl -w net.ipv4.conf.all.accept_redirects = 0<br /> Server# /sbin/sysctl -w net.ipv4.conf.all.send_redirects = 0</font></p>
<p><font color="#009999">Server# /sbin/sysctl -w net.ipv6.conf.all.accept_redirects = 0<br /> Server# /sbin/sysctl -w net.ipv6.conf.all.send_redirects = 0</font></p>
<p>The above disables ICMP Redirects globally on the server. However, if you want to disable on a per interface basis then in the above command, instead of using &quot;all&quot; use the inerface name (say &quot;eth0&quot;)</p>
<p><font color="#009999">Server# /sbin/sysctl -w net.ipv4.conf.eth0.accept_redirects = 0<br /> Server# /sbin/sysctl -w net.ipv4.conf.eth0.send_redirects = 0</font></p>
<p><font color="#009999">Server# /sbin/sysctl -w net.ipv6.conf.eth0.accept_redirects = 0<br /> Server# /sbin/sysctl -w net.ipv6.conf.eth0.send_redirects = 0</font></p>
<p>This will disable ICMP Redirects immediatly.</p>
<p>or even a simpler option would be to</p>
<p><strong><u><font color="#009900">2. Passing appropriate value (0 or 1) to the above kernel variables as follows:</font></u></strong></p>
<p><font color="#009999">Server# echo 0 &gt; /proc/sys/net/ipv4/conf/all/accept_redirects [for IPv4]<br /> Server# echo 0 &gt; /proc/sys/net/ipv4/conf/all/send_redirects [for IPv4]</font></p>
<p><font color="#009999">Server# echo 0 &gt; /proc/sys/net/ipv6/conf/all/accept_redirects [for IPv6]<br /> Server# echo 0 &gt; /proc/sys/net/ipv6/conf/all/send_redirects [for IPv6]</font></p>
<p>Again this can be used on a per interface basis as</p>
<p><font color="#009999">Server# echo 0 &gt; /proc/sys/net/ipv4/conf/eth0/accept_redirects [for IPv4]<br /> Server# echo 0 &gt; /proc/sys/net/ipv4/conf/eth0/send_redirects [for IPv4]</font></p>
<p><font color="#009999">Server# echo 0 &gt; /proc/sys/net/ipv6/conf/eth0/accept_redirects [for IPv6]<br /> Server# echo 0 &gt; /proc/sys/net/ipv6/conf/eth0/send_redirects [for IPv6]</font></p>
<p>However, these kernel changes made at runtime will be lost when the system reboots. So it is important that these are applied at boot time as well to ensure that the server is secure.</p>
<p><strong><u><font color="#009900">ICMP REDIRECT DISABLE AT BOOT TIME</font></u></strong></p>
<p>In order to disable ICMP Redirects at boot time,</p>
<p><strong><u><font color="#009900">1. Edit the /etc/sysctl.conf file</font></u></strong></p>
<p>Edit the /etc/sysctl.conf file and add the following lines:</p>
<p><font>In Debian and Ubuntu Linux:</font></p>
<p><font color="#009999">net/ipv4/conf/all/accept_redirects = 0 [for IPv4]<br /> net/ipv4/conf/all/send_redirects = 0 [for IPv4]</font></p>
<p><font color="#009999">net/ipv6/conf/all/accept_redirects = 0 [for IPv6]<br /> net/ipv6/conf/all/send_redirects = 0 [for IPv6]<br /> </font>&nbsp;<br /> Again, if you want to control ICMP redirects on a per interface basis then add the following lines (say for eth0):</p>
<p><font color="#009999">net/ipv4/conf/eth0/accept_redirects = 0 [for IPv4]<br /> net/ipv4/conf/eth0/send_redirects = 0 [for IPv4]</font></p>
<p><font color="#009999">net/ipv6/conf/eth0/accept_redirects = 0 [for IPv6]<br /> net/ipv6/conf/eth0/send_redirects = 0 [for IPv6]</font></p>
<p><font>In Redhat Enterprise Linux and Suse:</font></p>
<p><font color="#009999">net.ipv4.conf.all.accept_redirects = 0 [for IPv4]<br /> net.ipv4.conf.all.send_redirects = 0 [for IPv4]</font></p>
<p><font color="#009999">net.ipv6.conf.all.accept_redirects = 0 [for IPv6]<br /> net.ipv6.conf.all.send_redirects = 0 [for IPv6]</font><br /> &nbsp;<br /> Again, if you want to control ICMP redirects on a per interface basis then add the following lines (say for eth0):</p>
<p><font color="#009999">net.ipv4.conf.eth0.accept_redirects = 0 [for IPv4]<br /> net.ipv4.conf.eth0.send_redirects = 0 [for IPv4]</font></p>
<p><font color="#009999">net.ipv6.conf.eth0.accept_redirects = 0 [for IPv6]<br /> net.ipv6.conf.eth0.send_redirects = 0 [for IPv6]</font></p>
<p>This will allow the /etc/sysctl.conf be read by the /sbin/sysctl utility at the startup.</p>
<p><em>NOTE: In Debian and Ubuntu, this will be overiden by any options set in /etc/network/options as the /etc/init.d/networking script which sets the /etc/network/options file kernel paramters at boot time runs after the /etc/init.d/procps script which sets the kernel variable values specified in /etc/sysctl.conf file. It is advisable to make all change to /etc/sysctl.conf file instead of /etc/network/options file as this is being depreciated.</em></p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.itsyourip.com%2FSecurity%2Fhow-to-disable-icmp-redirects-in-linux-for-security-redhatdebianubuntususe-tested%2F';
  addthis_title  = 'How+to+Disable+ICMP+Redirects+in+Linux+for+security+%28Redhat%2CDebian%2CUbuntu%2CSuSe+tested%29';
  addthis_pub    = '';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
</div><!-- KonaBody -->]]></content:encoded>
			<wfw:commentRss>http://www.itsyourip.com/Security/how-to-disable-icmp-redirects-in-linux-for-security-redhatdebianubuntususe-tested/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Firewall Builder &#8211; Multiplatform Firewall Configuration Manager</title>
		<link>http://www.itsyourip.com/Security/firewall-builder-multiplatform-firewall-configuration-manager/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=firewall-builder-multiplatform-firewall-configuration-manager</link>
		<comments>http://www.itsyourip.com/Security/firewall-builder-multiplatform-firewall-configuration-manager/#comments</comments>
		<pubDate>Sat, 01 Dec 2007 20:14:52 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Opensource Firewall]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.itsyourip.com/Security/firewall-builder-multiplatform-firewall-configuration-manager/</guid>
		<description><![CDATA[Firewall Builder is an Opensource multi-vendor Firewall Configuration and Management GUI tool. It uses a set of policy compilers for the different firewalls supported. If you are a Network administrator supporting multiple sites and multiple firewall devices then you would know what difference a central Firewall Manager can make to the day to day task. [...]]]></description>
			<content:encoded><![CDATA[<div class="KonaBody"><p><!--adsense#content_336_280-->
<p>Firewall Builder is an Opensource multi-vendor Firewall Configuration and Management GUI tool. It uses a set of policy compilers for the different firewalls supported. If you are a Network administrator supporting multiple sites and multiple firewall devices then you would know what difference a central Firewall Manager can make to the day to day task. A Netscreen Security Manager for Junipers or the admin tool for checkpoints is an example, despite these being expensive commercial options from the very own vendors. Firewall Builder on the other hand a hetrogenous, vendor neutral configuration and management tool with support to more than one single platform and an easy design allowing expanding support more platforms.</p>
<p>Firewall Builder uses object-oriented approach, it helps administrator maintain a database of network objects and allows policy editing using simple drag-and-drop operations. Firewall Builder can generate configuration file for any supported target firewall platform from the same policy created in its GUI. This provides for both consistent policy management solution for heterogeneous environments and possible migration path.</p>
<p><span id="more-119"></span></p>
<p>Firewall Builder uses the same Object database (hosts,networks,services etc) for all the different vendor firewalls in an xml format and any change to any of the object will automatically update the rules on the policy sets and they only need to recompile the policies&nbsp; and apply to the firewall devices. Maintaing the Object Database in XML format and keeping the GUI and policy compilers completely independent makes it easy to expand support new firewall platforms.</p>
<p>In Firewall Builder, administrator works with an abstraction of firewall policy and NAT rules; software effectively &quot;hides&quot; specifics of particular target firewall platform and helps administrator focus on implementation of security policy. Backend software components, or policy compilers, can deduct many parameters of policy rules using information available through network and service objects and therefore generate fairly complex code for the target firewall, thus relieving administrator from having to remember all its details and limitations. Policy compilers can also run sanity checks on firewall rules and make sure typical errors are caught before generated policy is deployed.</p>
<p>Firewall Builder supports</p>
<ul>
<li>iptables on Linux (Kernel 2.4 &amp; Kernel 2.6)</li>
<li>ipfilter on Sun Solaris, FreeBSD and OpenBSD</li>
<li>ipfw on FreeBSD and MacOS X</li>
<li>pf on OpenBSD</li>
<li>CiscoPIX (commercial license)</li>
<li>Cisco IOS&nbsp; Access Control Lists (commercial license)</li>
<li>Linksys Firewall running sveasoft and OpenWrt firmware</li>
</ul>
<p>Firewall Builder can run on</p>
<ul>
<li>Redhat Linux, Mandrake Linux 10, Suse 9.1</li>
<li>FreeBSD 5.3</li>
<li>MacOS X</li>
<li>Windows XP SP1 and later</li>
</ul>
<p>Firewall Builder licensing is a dual-license model where all the opensource modules are available under GPL while the commercial modules are licensed under its own Netcitaadel End User licensing model.</p>
<p>The Firewall Builder software has great documentation and lots of How Tos, installation guides and a good FAQ to support this very good piece of software.</p>
<p>For more information and download, <a href="http://www.fwbuilder.org" target="_blank" title="Firewall Builder Multi vendor Firewall Configuration Management">click here</a> to visit the homepage of Firewall Builder.</p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.itsyourip.com%2FSecurity%2Ffirewall-builder-multiplatform-firewall-configuration-manager%2F';
  addthis_title  = 'Firewall+Builder+%26%238211%3B+Multiplatform+Firewall+Configuration+Manager';
  addthis_pub    = '';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
</div><!-- KonaBody -->]]></content:encoded>
			<wfw:commentRss>http://www.itsyourip.com/Security/firewall-builder-multiplatform-firewall-configuration-manager/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>ClarkConnect &#8211; OpenSource Firewall Intrusion Prevention networking and collabration suite</title>
		<link>http://www.itsyourip.com/networking/clarkconnect-opensource-firewall-intrusion-prevention-networking-and-collabration-suite/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=clarkconnect-opensource-firewall-intrusion-prevention-networking-and-collabration-suite</link>
		<comments>http://www.itsyourip.com/networking/clarkconnect-opensource-firewall-intrusion-prevention-networking-and-collabration-suite/#comments</comments>
		<pubDate>Thu, 29 Nov 2007 20:17:33 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Opensource Firewall]]></category>
		<category><![CDATA[Redhat]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[antiphising]]></category>
		<category><![CDATA[antispam]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[idp]]></category>
		<category><![CDATA[intrusion-prevention]]></category>
		<category><![CDATA[ipsec]]></category>
		<category><![CDATA[multiwan]]></category>
		<category><![CDATA[proxy]]></category>
		<category><![CDATA[snort]]></category>
		<category><![CDATA[squid]]></category>
		<category><![CDATA[vpn]]></category>

		<guid isPermaLink="false">http://www.itsyourip.com/networking/clarkconnect-opensource-firewall-intrusion-prevention-networking-and-collabration-suite/</guid>
		<description><![CDATA[ClarkConnect is an all-in-one Opensource networking suite from Point Clark Networks. It is a full blown security suite on one front with Stateful firewall protection, Intrusion Detection and prevention, Maile Gateway with Antivirus, Anti-spam and Anti-phishing support, proxy &#38; web content filtering, peer to peer connection filtering for web protection while is also a networking [...]]]></description>
			<content:encoded><![CDATA[<div class="KonaBody"><p><!--adsense#content_336_280-->
<p>ClarkConnect is an all-in-one Opensource networking suite from Point Clark Networks. It is a full blown security suite on one front with Stateful firewall protection, Intrusion Detection and prevention, Maile Gateway with Antivirus, Anti-spam and Anti-phishing support, proxy &amp; web content filtering, peer to peer connection filtering for web protection while is also a networking suite with IPSec and PPTP support, bandwdith and system monitoring and a server with web-server, Database server support, file &amp; print sharing, mail server, system and mail backup. All built on a cut down redhat linux with&nbsp;a good web interface.</p>
<p><span id="more-117"></span></p>
<p>ClarkConnect is an opensource winner with all the features are directly enabled by opensource packages.</p>
<p>The top features of ClarkConnect are</p>
<ul>
<li>Statefule Firewall with DMZ interface enabled, NAT and port forwarding support</li>
<li>Intrusion Detection (Snort) and Preention (snortsam)</li>
<li>Peer to Peer connection prevention</li>
<li>MultiWAN support with bandwidth monitoring</li>
<li>VPN support with IPSec and PPTP support</li>
<li>Webproxy, Content Filtering, Popup/banner adblocker</li>
<li>Email Server support (POP, IMAP and SMTP) and webmail support</li>
<li>Dns, DynDNS, DHCP Support</li>
<li>Mail Gateway with antispam (spamassasin,Dspam,greylisting), Antivirus (ClamA), phishing filter,&nbsp; Mail Disclaimer support</li>
<li>Groupware and Flexshare</li>
<li>Webserver (LAMP)</li>
<li>File and Print Sharing, FTP server</li>
<li>Network Backup</li>
</ul>
<p>For more detailed listing of features, <a href="http://www.clarkconnect.com/info/features.php" target="_blank" title="ClarkConnect opensource networking and firewall security">click here</a></p>
<p>ClarkConnect comes in three different editions as Enterprise, Office and Community editions. The Community edition is a free edition with no support for the serices and hence is good for Home and Small Office. The Office edition has all of the network and security features enabled with the exception of the Grouware support and the all enabled version is the Enterprise edition. While the Office and Enterprise editions are commercial, the cost is not very pricey.</p>
<p>For a comparision on the versions, <a href="http://www.clarkconnect.com/info/compare.php" target="_blank" title="ClarkConnect Opensource networking suite pricing">click here</a></p>
<p>A detailed <a href="http://www.clarkconnect.com/info/requirements.php" target="_blank" title="ClarkConnect OpenSource networking Suite Hardware">hardware requirement</a> can be found on ClarkConnect website with downloads available <a href="http://www.clarkconnect.com/downloads/" target="_blank" title="ClarkConnect OpenSource Networking Suite download">here</a>.</p>
<p><strong><u>A Reader&#39;s Toolbox</u></strong></p>
<p>For <a href="http://www.braindumps.net/exam/640-802.htm">640-802</a>, it is important to qualify both <a href="http://www.braindumps.net/exam/350-001.htm">350-001</a> as well as <a href="http://www.braindumps.net/exam/70-291.htm">70-291</a>. Still a number of individuals settle for <a href="http://www.braindumps.net/exam/70-649.htm">70-649</a> too.</p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.itsyourip.com%2Fnetworking%2Fclarkconnect-opensource-firewall-intrusion-prevention-networking-and-collabration-suite%2F';
  addthis_title  = 'ClarkConnect+%26%238211%3B+OpenSource+Firewall+Intrusion+Prevention+networking+and+collabration+suite';
  addthis_pub    = '';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
</div><!-- KonaBody -->]]></content:encoded>
			<wfw:commentRss>http://www.itsyourip.com/networking/clarkconnect-opensource-firewall-intrusion-prevention-networking-and-collabration-suite/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>redWall Firewall &#8211; Opensource Linux Firewall using an old PC</title>
		<link>http://www.itsyourip.com/Security/redwall-firewall-opensource-linux-firewall-using-an-old-pc/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=redwall-firewall-opensource-linux-firewall-using-an-old-pc</link>
		<comments>http://www.itsyourip.com/Security/redwall-firewall-opensource-linux-firewall-using-an-old-pc/#comments</comments>
		<pubDate>Thu, 29 Nov 2007 14:21:22 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Opensource Firewall]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.itsyourip.com/Security/redwall-firewall-opensource-linux-firewall-using-an-old-pc/</guid>
		<description><![CDATA[redWall Firewall is a free opensource firewall based on Gentoo linux distribution with Linux Kernel 2.6. redWall firewall runs from a bootable CD-ROM while the configs are saved on a USB Memory stick, Floppy drive or on the Hard Drive. Newer version has support to install the firewall on the Hard Disk. The redWall firewall [...]]]></description>
			<content:encoded><![CDATA[<div class="KonaBody"><p><!--adsense#content_336_280-->
<p>redWall Firewall is a free opensource firewall based on Gentoo linux distribution with Linux Kernel 2.6. redWall firewall runs from a bootable CD-ROM while the configs are saved on a USB Memory stick, Floppy drive or on the Hard Drive. Newer version has support to install the firewall on the Hard Disk. The redWall firewall has a good web interface.</p>
<p>Reporting on the firewall is based on a MySQL database (except for squid) and so presents the advantage of using the firewall also as a Management console or a logging console so multiple firewalls in the network can report back to the management station or do the logging onto the redWall firewall for better presentation and broader visibility of the whole network security.</p>
<p><span id="more-116"></span></p>
<p>Features include</p>
<ul>
<li>Stateful Firewall (iptables)</li>
<li>Proxy using Squid</li>
<li>Intrusion Detection System (IDS) using Snort</li>
<li>Mail gateway functionality with Virus scanning and Antivirus support</li>
<li>Support for Bridging, NAT</li>
<li>DNS support using dnsmasq</li>
<li>Traffic shaping</li>
<li>Network Analyzer using nTop and DarkStat</li>
<li>Network monitoring and Bandwidth monitoring using Zabbix and Jffnms</li>
<li>SNMP reporting using Cacti</li>
<li>Webmin support</li>
<li>Log analysis using BASE</li>
<li>Good reporting for Squid and rest of the logs using Sarg Report</li>
<li>Management/Logging console for multiple firewalls on the network</li>
</ul>
<p>There is not much documentation available on the website for redWall but given that the firewall can run off the CD-ROM (installable to Hard Disk) and that the configs can be saved onto a USB Memory Stick, Floppy or a Hard Disk, an old PC can certainly be enough to run a fully functional Firewall. Ofcourse, give some good hard disk space for Squid and/or for central logging (if used as a logging console)</p>
<p>The CD ISO image can be downloaded <a href="http://www.redwall-firewall.com/content/view/14/33/" target="_blank" title="redWall Opensource firewall">here</a>.</p>
<p>To install the Firewall onto the Hard Disk, run &quot;redwall-setup&quot; from the console and select &quot;INSTALLATION&quot; and follow the onscreen instructions.</p>
<p><strong><u>A Reader&#39;s Toolbox</u></strong></p>
<p>Normally after <a href="http://www.braindumps.net/exam/220-602.htm">220-602</a> a number of individuals go for <a href="http://www.braindumps.net/exam/1Y0-259.htm">1Y0-259</a> or the more advanced <a href="http://www.braindumps.net/exam/640-822.htm">640-822</a>. People seldom try for <a href="http://www.braindumps.net/exam/220-601.htm">220-601</a> as that only leads to <a href="http://www.braindumps.net/exam/70-293.htm">70-293</a>.</p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.itsyourip.com%2FSecurity%2Fredwall-firewall-opensource-linux-firewall-using-an-old-pc%2F';
  addthis_title  = 'redWall+Firewall+%26%238211%3B+Opensource+Linux+Firewall+using+an+old+PC';
  addthis_pub    = '';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
</div><!-- KonaBody -->]]></content:encoded>
			<wfw:commentRss>http://www.itsyourip.com/Security/redwall-firewall-opensource-linux-firewall-using-an-old-pc/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>pfSense &#8211; m0n0wall based OpenSource Firewall using old PC</title>
		<link>http://www.itsyourip.com/Security/pfsense-m0n0wall-based-opensource-firewall-using-old-pc/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=pfsense-m0n0wall-based-opensource-firewall-using-old-pc</link>
		<comments>http://www.itsyourip.com/Security/pfsense-m0n0wall-based-opensource-firewall-using-old-pc/#comments</comments>
		<pubDate>Wed, 28 Nov 2007 22:57:43 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Opensource Firewall]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Unix]]></category>
		<category><![CDATA[Wireless]]></category>

		<guid isPermaLink="false">http://www.itsyourip.com/Security/pfsense-m0n0wall-based-opensource-firewall-using-old-pc/</guid>
		<description><![CDATA[pfSense is yet another opensource firewall which can turn your old PC into a fully functional Firewall. pfSense opensource firewall is based on the m0n0wall opensource embedded firewall with all the good features of m0n0wall and advanced addition features. pfSense uses OpenBSD&#39;s ported packet filter, FreeBSD 6.1 ALTQ (HSFC) for excellent packet queueing and integrated [...]]]></description>
			<content:encoded><![CDATA[<div class="KonaBody"><p><!--adsense#content_336_280-->
<p>pfSense is yet another opensource firewall which can turn your old PC into a fully functional Firewall. pfSense opensource firewall is based on the m0n0wall opensource embedded firewall with all the good features of m0n0wall and advanced addition features.</p>
<p>pfSense uses OpenBSD&#39;s ported packet filter, FreeBSD 6.1 ALTQ (HSFC) for excellent packet queueing and integrated package managegement system for extending with new features.</p>
<p><span id="more-115"></span> </p>
<p>pfSense can be downloaded a Live CD which is also an installation CD or as an installation ISO for developer edition or an Embedded edition. For more info on the download packages, <a href="http://wiki.pfsense.com/wikka.php?wakka=WhichVersionIsRightForMe" target="_blank" title="pfSense OpenSource Firewall">click here</a>.</p>
<p>The software itself can be downloaded from <a href="http://www.pfsense.com/index.php?id=22" target="_blank" title="pfSense opensource firewall download">here</a></p>
<p>A good set of install instructions are available <a href="http://www.pfsense.com/index.php?id=36" target="_blank" title="pfsense Opensource firewall installa instructions">here</a></p>
<p>More information on Hardware, minimum requirements and recommended vendor products, visit pfSense <a href="http://www.pfsense.com/" target="_blank" title="pfsense Opensource Firewall home">here</a></p>
<p>In additional to the existing features on m0n0wall firewall, pfSense has the special additional features. The following are some of the key additional features:</p>
<ul>
<li>Wireless a/b/g using wpa_supplicant with turbo, WEP, WPA-E/PSK and WPA2 (TKIP) support. Advanced support for wireless devices including HostAP-mode, hardware-encryption if supported by driver, mac-filtering, non-broadcasting SSID with FreeBSD6 supported wireless devices (atheros recommended for full functionality)</li>
<li>Incoming/outgoing load balancing pools</li>
<li>Multiple WAN Support</li>
<li>PPPoE Server</li>
<li>Setup wizard and package using xml -&gt; web gui toolkit</li>
<li>Realtime settings change to avoid reboots</li>
<li>pf for openbsd&#39;s packet filter</li>
<li>CARP &#8211; for failover and clustersyncing (rules, trafficshaper, nat, IPSEC SAs&#8230;)</li>
<li>failovercapable DHCP-Server with advanced settings (specify gateway, DNS, WINS)</li>
<li>Systemstatus with realtimegraphs including SWAP usage monitor</li>
<li>ALTQ traffic shaping with integrated magic shaper wizard with Queuegraphs for Trafficshaper</li>
<li>FTP-Proxy using Squid Transparent proxy</li>
<li>proxy/masquerading for SIP-protocol using siproxd</li>
<li>Anti-Spam-Proxy using assp</li>
<li>Fake SMTP-Server as Spam-Tarpit using spamd</li>
<li>Networkscanner for security auditing using nmap</li>
<li>Enhanced traceroute using mtr</li>
<li>enhanced configuration-system featuring a configuration history and partial config down-/uploads</li>
<li>converting PF-status-massages to Cisco NetFlow-Datagrams using pfflowd</li>
<li>PFStat Graphing</li>
<li>Enhanced network history data using NTOP</li>
<li>STunnel to wrap standard ports with SSL</li>
<li>arpwatch to watch ethernet/ip-adress-pairings</li>
<li>freeradius to Radiusserver</li>
<li>iperf/netio for bandwidth-measuring</li>
</ul>
<p><strong><u>A Reader&#39;s Toolbox</u></strong></p>
<p>After <a href="http://www.braindumps.net/exam/SY0-101.htm">SY0-101</a>, a small number of individuals are content with their <a href="http://www.braindumps.net/exam/N10-003.htm">N10-003</a> where as the rest go on to study <a href="http://www.braindumps.net/exam/70-620.htm">70-620</a>. This group later covers <a href="http://www.braindumps.net/exam/350-030.htm">350-030</a> as well.</p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.itsyourip.com%2FSecurity%2Fpfsense-m0n0wall-based-opensource-firewall-using-old-pc%2F';
  addthis_title  = 'pfSense+%26%238211%3B+m0n0wall+based+OpenSource+Firewall+using+old+PC';
  addthis_pub    = '';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
</div><!-- KonaBody -->]]></content:encoded>
			<wfw:commentRss>http://www.itsyourip.com/Security/pfsense-m0n0wall-based-opensource-firewall-using-old-pc/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>m0n0wall &#8211; Opensource embedded Firewall turns a PC into firewall</title>
		<link>http://www.itsyourip.com/Security/m0n0wall-opensource-embedded-firewall-turns-a-pc-into-firewall/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=m0n0wall-opensource-embedded-firewall-turns-a-pc-into-firewall</link>
		<comments>http://www.itsyourip.com/Security/m0n0wall-opensource-embedded-firewall-turns-a-pc-into-firewall/#comments</comments>
		<pubDate>Wed, 28 Nov 2007 18:24:57 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[OpenSource]]></category>
		<category><![CDATA[Opensource Firewall]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Unix]]></category>
		<category><![CDATA[Wireless]]></category>

		<guid isPermaLink="false">http://www.itsyourip.com/Security/m0n0wall-opensource-embedded-firewall-turns-a-pc-into-firewall/</guid>
		<description><![CDATA[m0n0wall is a free opensource embedded firewall that runs on embedded PCs (recommended) and other generic standard PC workstations that can run FreeBSD or rather supported by FreeBSD. m0n0wall firewall provides most of the features provided by a commercial firewall. Click here for a list of supported FreeBSD/i386 hardware. For more information on the hardware [...]]]></description>
			<content:encoded><![CDATA[<div class="KonaBody"><p><!--adsense#content_336_280-->
<p>m0n0wall is a free opensource embedded firewall that runs on embedded PCs (recommended) and other generic standard PC workstations that can run FreeBSD or rather supported by FreeBSD. m0n0wall firewall provides most of the features provided by a commercial firewall.</p>
<p><span id="more-114"></span></p>
<p><a href="http://www.freebsd.org/releases/4.11R/hardware-i386.html" target="_blank" title="m0n0wall - FreeBSD hardware support list">Click here</a> for a list of supported FreeBSD/i386 hardware.</p>
<p>For more information on the hardware details m0n0wall <a href="http://m0n0.ch/wall/hardware.php" target="_blank" title="m0n0wall - Opensource embedded firewall hardware support">click here</a></p>
<p>M0n0wall is based on a bare-bones version of FreeBSD with mini-httpd webserver for web GUI and PHP (with CGI support) for boot time configuration. The complete configuration is stored in XML format. This is likely the only softwar where PHP does the boot time configuration instead of Shell scripts.</p>
<p>The image file for installation is of 6MB in size including the core freebsd and the required components and utilities that offers most if not all the features of a commercial firewall appliance. There are seperate image files for each of the different hardware platforms supported. For more information on downloads, <a href="http://m0n0.ch/wall/downloads.php" target="_blank" title="m0n0wall - Opensource embedded firewall download">click here</a></p>
<p>The whole software package can be run on a compact flash card (atleast 8M in size) or on a IDE hard disk. The recommended memory is atleast 64MB. The installation procedures are well documented.</p>
<p>For details on installation procedures <a href="http://m0n0.ch/wall/installation.php" target="_blank" title="m0n0wall opensource emedded firewall installation">click here</a></p>
<p>The Main features of m0n0wall firewall are,</p>
<ul>
<li>Stateful Packet Filtering</li>
<li>Web Interface (SSL) and Serial Console for administration (mini-httpd)</li>
<li>Wireless Support</li>
<li>Captive Portal</li>
<li>802.1Q VLAN&nbsp; support</li>
<li>Stateful Packet Filtering using ipfilter</li>
<li>NAT/PAT, Static Router, Host Aliases support</li>
<li>DHCP client, PPPoE, PPTP and Telstra BigPond Cable support on the WAN interface</li>
<li>IPsec IKE VPN using Racoon with support for hardware crypto cards, mobile clients and certificates</li>
<li>PPTP VPN (with RADIUS server support)</li>
<li>DHCP server and <a href="http://www.itsyourip.com/cisco/dhcp-relay-agent-for-subnets-without-a-dhcp-server/" target="_blank" title="DHCP Relay Agent">DHCP-Relay</a> (ISC DHCP)</li>
<li>Caching DNS forwarder using dnsmasq</li>
<li>DynDNS client and RFC 2136 DNS updater using ez-ipupdate</li>
<li>Traffic shaping</li>
<li>SVG-based traffic grapher</li>
<li>firmware upgrade through the web browser</li>
<li>Wake on LAN</li>
<li>Configuration backup/restore</li>
</ul>
<p>For more detailed feature list, <a href="http://m0n0.ch/wall/features.php" target="_blank" title="m0n0wall opensource embedded firewall features">click here</a></p>
<p>For more information on this FreeBSD based open source firewall, please <a href="http://m0n0.ch/wall/" target="_blank" title="m0n0wall opensource embedded firewall home">click here</a></p>
<p><strong><u>A Reader&#39;s Toobox</u></strong></p>
<p>After <a href="http://www.braindumps.net/exam/70-290.htm">70-290</a>, a small number of professionals who wants to study <a href="http://www.braindumps.net/exam/70-296.htm">70-296</a> move on to the next level i.e. <a href="http://www.braindumps.net/exam/70-270.htm">70-270</a>, where as the rest go with the <a href="http://www.braindumps.net/exam/642-901.htm">642-901</a>.</p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.itsyourip.com%2FSecurity%2Fm0n0wall-opensource-embedded-firewall-turns-a-pc-into-firewall%2F';
  addthis_title  = 'm0n0wall+%26%238211%3B+Opensource+embedded+Firewall+turns+a+PC+into+firewall';
  addthis_pub    = '';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
</div><!-- KonaBody -->]]></content:encoded>
			<wfw:commentRss>http://www.itsyourip.com/Security/m0n0wall-opensource-embedded-firewall-turns-a-pc-into-firewall/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>IPCop Firewall &#8211; Opensource Linux turns old PC into Firewall</title>
		<link>http://www.itsyourip.com/Security/ipcop-firewall-opensource-linux-turns-old-pc-into-firewall/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=ipcop-firewall-opensource-linux-turns-old-pc-into-firewall</link>
		<comments>http://www.itsyourip.com/Security/ipcop-firewall-opensource-linux-turns-old-pc-into-firewall/#comments</comments>
		<pubDate>Tue, 27 Nov 2007 20:07:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[OpenSource]]></category>
		<category><![CDATA[Opensource Firewall]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Wireless]]></category>

		<guid isPermaLink="false">http://www.itsyourip.com/Security/ipcop-firewall-opensource-linux-turns-old-pc-into-firewall/</guid>
		<description><![CDATA[IPCop Firewall &#8211; Bad Packets Stop here!!!&#160; IPCop Firewall is a well known&#160;Opensource Linux distribution built to protect Home and SOHO networks from hackers and potential intruders on the Internet. IPCop can run a old PC and can be installed and be operational within minutes. Please click here for more information on the Hardware compatibility [...]]]></description>
			<content:encoded><![CDATA[<div class="KonaBody"><p><!--adsense#content_336_280-->
<p>IPCop Firewall &#8211; Bad Packets Stop here!!!&nbsp;</p>
<p>IPCop Firewall is a well known&nbsp;Opensource Linux distribution built to protect Home and SOHO networks from hackers and potential intruders on the Internet. IPCop can run a old PC and can be installed and be operational within minutes.</p>
<p><span id="more-113"></span></p>
<p>Please <a href="http://www.ipcop.org/index.php?module=pnWikka&amp;tag=IPCopHCLv01" target="_blank" title="IPCop Firewall HCL">click here</a> for more information on the Hardware compatibility list. Installation is fairly straight forward. Involves downloading the ISO image and burn it to a CD and start the hardware with the installation media and follow the onscreen instructions. A detailed installation instruction is <a href="http://www.ipcop.org/1.4.0/en/install/html/" target="_blank" title="IPCop Firewall Installation">here</a>.</p>
<p>The IPCop firewall runs on Linux Kernel 2.4 and is a stateful firewall (1.3 and later) based on Linux IPTables. The IPCop firewall has a nice web interface from where almost all the configurations can be done.</p>
<p>While IPCop firewall is primarily a router and Stateful firewall, it has most of the common features found on commercial hardware firewall appliances. Some of the key features are</p>
<ul>
<li>Stateful Firewall using IPTables</li>
<li>Intrusion Detection System using Snort</li>
<li>IP, Web and FTP proxy using Squid Proxy</li>
<li>Dynamic DNS Support</li>
<li>DNS Forwarding and DHCP using dnsmasq</li>
<li>IPSec VPN supporting both roadwarrior and Site to Site using OpenSwan</li>
<li>Wireless supported a DMZ on the firewall using the Wireless_Tools (opensource Wireless tools sponsored and supported by HP)</li>
<li>Traffic Shaping on the External Internet facing interface (RED)</li>
<li>SSH using OpenSSH</li>
<li>Local and remote logging support</li>
<li>NTP Server/Client support</li>
<li>NAT Helper and port forwarding support</li>
</ul>
<p>The IPCop Firewall has a very good <a href="http://www.ipcop.org/index.php?module=pnWikka&amp;tag=IPCopDocumentation" target="_blank" title="IPCop Firewall - Documentation">documentation</a> and <a href="http://www.ipcop.org/index.php?name=FAQ" target="_blank" title="IPCop Firewall - FAQ">FAQ</a> on its website actively supported by the Opensource community. <a href="http://www.itsyourip.com/opensource-firewall/smoothwall-express-30-opensource-firewall/" target="_blank" title="Smoothwall Express Opensource firewall">Smoothwall Express</a> is a opensource firewall based on th IPCop firewall</p>
<p>For more information and download, please <a href="http://www.ipcop.org/" target="_blank" title="IPCop Firewall - Opensource linux firewall">click here</a></p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.itsyourip.com%2FSecurity%2Fipcop-firewall-opensource-linux-turns-old-pc-into-firewall%2F';
  addthis_title  = 'IPCop+Firewall+%26%238211%3B+Opensource+Linux+turns+old+PC+into+Firewall';
  addthis_pub    = '';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
</div><!-- KonaBody -->]]></content:encoded>
			<wfw:commentRss>http://www.itsyourip.com/Security/ipcop-firewall-opensource-linux-turns-old-pc-into-firewall/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
