Slashdot Mirror


SmoothWall 2.0 Linux-Based Firewall Released

thegraham writes "Despite some earlier server problems, SmoothWall 2.0 has been released this evening - there are also release notes available. SmoothWall is 'a firewall operating system distribution based on Linux, enabling a low-end, possibly otherwise redundant, Intel and compatible PC to become a hardened Internet firewall', and changes from version 1 include: 2.4 kernel, new web interface, improved networking and many bugs corrected through the Beta program."

13 of 351 comments (clear)

  1. Re:OS? by pe1chl · · Score: 4, Insightful

    Hardware firewall?
    You probably mean a box with a microcontroller running a dedicated firewall operating system.

  2. new? by oohp · · Score: 2, Insightful

    And this is new how? There are dozens of firewall distros out there, does SmoothWall have anything special or innovative?

  3. linksys box? by Anonymous Coward · · Score: 3, Insightful

    A rather newbie sounding question but can anyone explain solid reasons to use this instead of the standard linksys firewall that comes with the router? Note that I'm talking about a home user with less critical requirements than a business.

    1. Re:linksys box? by Hayzeus · · Score: 3, Insightful
      A rather newbie sounding question but can anyone explain solid reasons to use this instead of the standard linksys firewall that comes with the router? Note that I'm talking about a home user with less critical requirements than a business.

      I used to use a Linux box for firewalling/masquerading and had to switch to a LinkSys because of DHCP issues with my broadband provider. One big advantage of the Linux setup was the additional functionality offered by the IP masquerading helper modules; stuff that couldn't normally be masqueraded (CuSeeMe comes to mind) could have "helper" kernel modules that allowed traffic to be masqueraded properly. You could also do web caching to disk on the same machine -- obviously not possible with the linksys.

  4. Re:OS? by tacocat · · Score: 4, Insightful

    Because software solutions are too late. The culprit is already at your machine

    And hardware solutions have two problems that I've personally seen happen.

    1. If they are found to have a security flaw in them, the company will not make the effort to reveal to the community the need for a security upgrade in every case.
    2. I can install smoothwall/ip-cop for free on a machine I can pick up for free. It comes with the capability of supporting a DMZ/LAN configuration (3 NICs). This costs big $$$ in hardware

    There are very distinct advantages to this approach. BTW they also have squid, which hardware devices can't provide.

  5. Re:Developer issues/fork by jazman_777 · · Score: 5, Insightful
    So really, if you want to use Smoothwall, better read hard or get a thicker skin somewhere. Perhaps that's good advice for the rest of us anyway.

    But Morell was in a league of his own. Most rude types are simply rude. Morell was the strutting peacock of rudeness amongst a rabble of sparrows and starlings.

    --
    Slashdot: Failed Car Analogies. Amateur Lawyering. Anecdote Battles.
  6. Re:Smoothwall support by wpanderson · · Score: 2, Insightful

    There's no requirement to donate or anything of the sort. If you'd like to purchase the company's commercial software, that's great, but the point of open source is that it's open, free, and libre :)

    Please don't perpetuate stale attitudes!

    --
    neuro at well dot com (when I post, it's my opinions, no-one elses)
  7. Re:Google to the rescue by Daemonik · · Score: 2, Insightful

    It's really hard to run Snort from a floppy distro.

    Also, think about it, if the distro is a 33mb ISO chances are damn good that it won't install to a floppy.

  8. Re:I had a job interview with these people by Daemonik · · Score: 4, Insightful
    IMO an experienced admin should take a minimal install of his favorite generic Linux/BSD distro, and build from there. Smoothwall is good for the less experienced though, who need an out of the box solution right now, not after 6 months googleing :-)
    No, a junior admin should take the time to build a firewall from scratch.

    An experienced admin is much too busy playing Nethack and downloading pr0n from his bosses logins while running a couple of Quake servers off the company T1 to devote that kind of time to a project.

  9. Re:I use the forked IPCop by Anonymous+Psychopath · · Score: 2, Insightful

    I too switched from Smoothwall to IPCop after an, um, interaction with Morell. Although Smoothwall is a good product, IPCop is equally good (if not better), and I've been using it without any problems for quite some time. Frankly, I'd crawl through glass in order to avoid anything with Morell's name on it.

    --

    Eagles may soar, but weasels don't get sucked into jet engines.

  10. Such forgiveness... by The+Tyro · · Score: 3, Insightful

    One of the Smoothwall guys just apologized to you (even though he has no way of verifying your "I was mistreated" story) in a public forum, admitted they were wrong, and did it in front of several hundred thousand slashdotters (something he didn't have to do, BTW)... and you won't even consider the software? Ever?

    Projects evolve, abrasive people are often forced out over time. Seems to me you are missing out on a potentially useful tool, based on a past beef with some guys who are no longer there...

    I'm not saying you don't have the right to feel they way you do... it just doesn't seem very pragmatic.

    --
    Even if a man chops off your hand with a sword, you still have two nice, sharp bones to stick in his eyes.
  11. Do you want to learn? by The+Tyro · · Score: 3, Insightful

    Buying a "hardware firewall" (cheaper ones are just an NAT box) is easy, but teaches you nothing.

    Honestly... there is no substitute for building your own stuff, particularly if you want to increase your understanding of networking and security. If you don't have time for that kind of thing, or just don't want the hassle (you say hassle, I say "learning experience") of rolling your own, then buy the Linksys/Dlink/Netgear box and be done with it.

    You will get far more options and much better control with the one you build yourself... but it doesn't come for free; it takes effort on your part. Seriously... build your own, then set up an ethernet tap with Snort to see what's coming and going on your network. The latter step with Snort personally taught me more about networking, protocols, and packets than any Man-page or article.

    Build it... you'll be amazed at what it does for your networking/security skills.

    --
    Even if a man chops off your hand with a sword, you still have two nice, sharp bones to stick in his eyes.
  12. Re:I use this one at home by BlackHawk-666 · · Score: 2, Insightful

    I think it's more likely to be the other way around, whereby they become a victim of their own success. When a project gets successful all sorts of noobs come along and ask the same dumb questions that are covered on the boards and in the FAQs. Developers get tired of having to repeat the answers and even RTFM and RTFF get tiring, so they tend to get shorter and snappier in their replies.

    --
    All those moments will be lost in time, like tears in rain.