Can we build our own software based firewall ?

https://www.fortinet.com/resources/cyberglossary/firewall

Learn what a firewall is, why it is important, how it works, and firewall best practices. Learn how a firewall can ensure the data is harmless and prevent data from being stolen or compromised.

4 points · 17 comments · view on lemmy.world

17 Comments

cmnybo@discuss.tchncs.de · 30 pts · 92d (12 replies)

There are a number of good FOSS options like OPNsense, OpenWrt, and IPFire. That article looks like an ad for some commercial software.

LeTak@feddit.org · 6 pts · 92d (8 replies)

I used OpnSense, OpenWRT and PFsense. Can’t really complain for home lab. But OpenWRT should not be used as a full UTM FW. It is more of a router and AccessPoint software. OpnSense and PFsense are both good options. Where OpnSense goes more into UTM FW with Plugins IDS/IPS stuff. I used PFsense only for IP based filtering but I know it can do more than that.

muusemuuse@sh.itjust.works · 2 pts · 92d (2 replies)

I could never get opnsense or openWRT to perform at full speed on gigabit WAN

LeTak@feddit.org · 2 pts · 92d (1 reply)

I also had trouble with that. I had to build some QoS pipes and query’s in OpnSense to reach 1Gbit/s. By now I upgraded my setup with an Intel N100 and 16GB RAM. It’s more than enough for OpnSense

muusemuuse@sh.itjust.works · 1 pts · 92d

I have tried on a Ryzen 5800xt virtualized and bare metal trying 3 different NICs. My firewalla purple still beats it and that infuriates me.

anamethatisnt@sopuli.xyz · 2 pts · 92d (1 reply)

You can run Suricata on pfsense too

LeTak@feddit.org · 1 pts · 92d

Yes. Does PfSense have something like OpenCentral for stack management?

MastKalandar@feddit.online · 1 pts · 92d (2 replies)

Basically l'm looking for a firewall that can push out attacks...... Like spams.......

LeTak@feddit.org · 4 pts · 92d (1 reply)

I use OpnSense with Suricata and CrowdSec for that kind of job. But nothing works out of the box in that segment. You have to learn how to setup your environment for your requirements. There a many tutorials and forums, you just have to dig around and find what you need.

MastKalandar@feddit.online · 1 pts · 88d

@Jerry@feddit.online do you see this ??

chris@l.roofo.cc · 4 pts · 92d

Well it is written by fortinet who has a well known commercial firewall appliance. So it probably is an ad.

MastKalandar@feddit.online · 3 pts · 92d

Thanks for those links.

dan@upvote.au · 2 pts · 92d

It's not FOSS, but MikroTik's RouterOS is pretty good. Decent alternative to opnsense. It's the exact same OS as on their routers and switches.

solrize@lemmy.ml · 2 pts · 92d (3 replies)

Iptables ?

nibbler@discuss.tchncs.de · 1 pts · 91d (2 replies)

Old school

frongt@lemmy.zip · -1 pts · 91d (1 reply)

ipchains is old school

nibbler@discuss.tchncs.de · 1 pts · 91d

ipfwadm ftw