[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[no subject]
- <!--x-content-type: text/plain -->
- <!--x-date: Wed, 09 Nov 2005 14:03:39 -0500 -->
- <!--x-from-r13: fzrnqfcnz100 ng fcrrqsnpgbel.arg (Yrvgu [vyyre) -->
- <!--x-message-id: [email protected] -->
- <!--x-reference: [email protected] -->
- <!--x-reference: [email protected] --> "http://www.w3.org/TR/html4/loose.dtd">
- <!--x-subject: [ale] Linux versus OpenBSD for enterprise firewalls -->
- <li><em>date</em>: Wed, 09 Nov 2005 14:03:39 -0500</li>
- <li><em>from</em>: smeadspam100 at speedfactory.net (Keith Miller)</li>
- <li><em>in-reply-to</em>: <<a href="msg00142.html">[email protected]</a>></li>
- <li><em>references</em>: <<a href="msg00137.html">[email protected]</a>> <<a href="msg00142.html">[email protected]</a>></li>
- <li><em>subject</em>: [ale] Linux versus OpenBSD for enterprise firewalls</li>
- Consider:
1) Release cycle.
Openbsd has them every 6 months and only release patches for current and
last version. This has the effect of making your OS unsupported after a
year (I've seen them issue patches for 2 versions back..but I wouldn't count
on it).
2). Patching
Openbsd uses patches. For routers/Nat/fw boxes this usually means you
either add a compiler to the unit (boo!) or compile the binaries on another
machine (my personal tactic).
3). Hardware support
Both do great here but look at what your planning on running on and make
sure they support it well (this is kinda obvious but there are surprises).
4) Meeting your specs
Do you require redudancy? Bandwidth shaping? Bonding? Failover?
Proxying? Wireless AP? IPSEC? Bascially who's going to meet your spec
the best.
Personally I've run openbsd on my routers for the last 5 years. Mostly out
of comfort and I don't have a heavy spec. I remind you of something I
mentioned at InstallFest. If your doing a fresh install with no previous
expectations, your have a great deal of latitude to implement things.
However, if your replacing an exisiting service (or unit) make sure you meet
the expectations of the systems and people who used that old unit. Are there
services or features that the Raptor offered that people or systems relied
on? Different is ok..just make sure you know ahead of time the differences
so you can educate.
Hope this helps a bit.
W. K. Miller
Michael H. Warfield wrote:
> On Wed, 2005-11-09 at 08:30 -0500, John Wells wrote:
>
>>Any opinions from the security guys on the list? I'm seeking to rid our
>>company of a nasty Symantec Raptor firewall, and of the numerous options
>>we're considering, Linux/iptables and OpenBSD/pf keep coming up. Any
>>thoughts?
>
>
> You would probably do well, either way. Which are you more comfortable
> with in administering?
>
>
>>Thanks,
>>John
>
>
> Mike
>
>
> ------------------------------------------------------------------------
>
> _______________________________________________
> Ale mailing list
> Ale at ale.org
> <a rel="nofollow" href="http://www.ale.org/mailman/listinfo/ale">http://www.ale.org/mailman/listinfo/ale</a>
</pre>
<!--X-Body-of-Message-End-->
<!--X-MsgBody-End-->
<!--X-Follow-Ups-->
<hr>
<!--X-Follow-Ups-End-->
<!--X-References-->
<ul><li><strong>References</strong>:
<ul>
<li><strong><a name="00137" href="msg00137.html">[ale] Linux versus OpenBSD for enterprise firewalls</a></strong>
<ul><li><em>From:</em> jb at sourceillustrated.com (John Wells)</li></ul></li>
<li><strong><a name="00142" href="msg00142.html">[ale] Linux versus OpenBSD for enterprise firewalls</a></strong>
<ul><li><em>From:</em> mhw at wittsend.com (Michael H. Warfield)</li></ul></li>
</ul></li></ul>
<!--X-References-End-->
<!--X-BotPNI-->
<ul>
<li>Prev by Date:
<strong><a href="msg00150.html">[ale] tux magazine</a></strong>
</li>
<li>Next by Date:
<strong><a href="msg00152.html">[ale] tux magazine</a></strong>
</li>
<li>Previous by thread:
<strong><a href="msg00142.html">[ale] Linux versus OpenBSD for enterprise firewalls</a></strong>
</li>
<li>Next by thread:
<strong><a href="msg00158.html">[ale] Linux versus OpenBSD for enterprise firewalls</a></strong>
</li>
<li>Index(es):
<ul>
<li><a href="maillist.html#00151"><strong>Date</strong></a></li>
<li><a href="threads.html#00151"><strong>Thread</strong></a></li>
</ul>
</li>
</ul>
<!--X-BotPNI-End-->
<!--X-User-Footer-->
<!--X-User-Footer-End-->
</body>
</html>