1823179 Members
3571 Online
109647 Solutions
New Discussion юеВ

Re: software firewall

 
SOLVED
Go to solution
Thomas Schler_1
Trusted Contributor

software firewall

We need a kind of software firewall that rejects packages that we don't want to receive. We are already using inetd.sec.

Does it make sense to have a software firewall in addition? Can you give me recommendations for software products?

We are running HPUX 10.20 on servers (K460).
no users -- no problems
7 REPLIES 7
A. Clay Stephenson
Acclaimed Contributor

Re: software firewall

Hi Thomas:

I've used Checkpoint's Firewall-1 for quite a while and it is an excellent product and is rock solid under 10.20. The rule setup and maintenance is fairly simple and ther GUI interface makes life pretty easy.

Clay
If it ain't broke, I can fix that.
Paula J Frazer-Campbell
Honored Contributor

Re: software firewall

Hi Thomas

For the best security a firewall should be a standalone machine which does nothing else.

Firewall 1 is the bees knees (very good)

;-)

Paula
If you can spell SysAdmin then you is one - anon
Brian Hackley
Honored Contributor
Solution

Re: software firewall

Thomas,

For 10.20 the basic choices are Checkpoint Firewall-1, Raptor Firewall or TIS Gauntlet. For 11.0 the choices are augmented by the HP product:
"IPFilter/9000, A.03.05.01, included with the HP-UX June 2001 Application CD.

"HP IPFilter/9000, product number B9901AA, is a system firewall that filters the IP level packets to control what packets are allowed to travel in or out of a machine. It works as a security defense by cutting down on the number of exposure points on a machine. "

I was not able to find IPFilter on the software.hp.com website, but it *is* on the Application CD's if you want to look at it.

Hope this helps,

-> Brian Hackley
Ask me about telecommuting!
Mike Hassell
Respected Contributor

Re: software firewall

Thomas,

Although my fellow HP-UXers out there may not like my answer here, I'd have to recommend running Linux 2.4, with a distribution of your choice (RedHat/Mandrake/SuSE). If you need to run it on a K470 then Checkpoint FW-1 is a great solution, however if you want a cheaper and still solid solution, I would recommend Linux for this task, here's why:

1. Linux 2.4 Kernel offers iptables, which provides a "stateful" firewall.
2. Easy to configure.
3. Great performance.
4. Very little associated cost.

While basic packet filtering will do, stateful firewalls take packet filtering to the next level by analyzing more than just the packet header and look for trends of abnormal usage which may represent a threat.

I'm no expert in this field, so take my info for what it's worth, but I think a Linux 2.4 box with a strong set of rules using iptables is a competitive solution for what you're after. It offers an inexpensive solution that provides a high level of security. If you're interested in using iptables for your firewall, be sure to check out the tutorial here:

http://people.unix-fu.org/andreasson/index.html

It's not perfect, but neither is FW-1 :)

- Mike
The network is the computer, yeah I stole it from Sun, so what?
Donna Snow
Occasional Advisor

Re: software firewall

HP has provided IPFilter/9000 with HP-UX 11.0 and 11i quarterly application releases on the application CD since March 2001.

It will be available for download in December from software depot, and continue to be in the application CD.

Donna Snow
Occasional Advisor

Re: software firewall

IPFilter/9000, a free product for hp-ux, will be available for download on Nov 13 from software depot, http://www.software.hp.com

It has better quality and performance than the version from the public domain.
Sanjay_6
Honored Contributor

Re: software firewall