Jul 102008
 

Up till now I’ve been run­ning the home fire­wall and a couple of minor web­sites from an old (1996 or there­abouts) Pen­ti­um 3 box in the base­ment, that uses Debi­an. It seems to work reas­on­ably well, and has been fend­ing off bots and oth­er threats with adequate fero­city. There seems no reas­on, how­ever, to think that the num­ber of attacks will decrease in the next little while, and every reas­on to sus­pect that one of these days the hard disk will fail, leav­ing me without a fire­wall. The web­sites are backed up and eas­ily restor­able, the time to set up a fire­wall and get it work­ing with a PPPoE con­nec­tion to an ISP that does­n’t under­stand Linux is what will take the time.

So I’ve been won­der­ing about rejig­ging the whole net­work, get­ting an off-the-shelf hard­ware firewall/router that can feed into the wire­less router. I’m a little para­noid about get­ting some­thing that is secure but not intend­ing to spend thou­sands. We’ve blocked all ports except the neces­sary ones on the sys­tem right now, except for allow­ing SSH access in and out, and, of course, port 80 for the web sites. Secur­ity will be par­tic­u­larly import­ant as the kids move into the teen­age years and start want­ing to down­load stuff.

I’m look­ing for some advice here. Do I need any­thing more than NAT, DMZ, and for­ward­ing appro­pri­ate ports to intern­al serv­ers, which I can get from stand­ard con­sumer-level router/firewalls? Any par­tic­u­larly good brands and mod­els I should look for?

/* ]]> */