Unix Technical Forum

Firewall + Bandwidth Throttle combo?

This is a discussion on Firewall + Bandwidth Throttle combo? within the Slackware Linux Support forums, part of the Unix Operating Systems category; --> Put together a Slack PC with several NICs to use as a router/switch. Need both a firewall and bandwidth ...


Go Back   Unix Technical Forum > Unix Operating Systems > Slackware Linux Support

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 02-20-2008, 06:38 AM
macusr023@yahoo.com
 
Posts: n/a
Default Firewall + Bandwidth Throttle combo?

Put together a Slack PC with several NICs to use as a router/switch.
Need both a firewall and bandwidth capper (have both separately). Has
anyone heard of a combo package? Searched sourceforge and google but
only came up with high end commercial products.

If not, I'll go ahead with both ... Thanks in advance

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 02-20-2008, 06:39 AM
buck
 
Posts: n/a
Default Re: Firewall + Bandwidth Throttle combo?

On 3 Mar 2005 07:01:00 -0800, macusr023@yahoo.com wrote:

>Put together a Slack PC with several NICs to use as a router/switch.
>Need both a firewall and bandwidth capper (have both separately). Has
>anyone heard of a combo package? Searched sourceforge and google but
>only came up with high end commercial products.
>
>If not, I'll go ahead with both ... Thanks in advance


Don't know of any package, but if you could configure a box with
"several" NICs you should be able to roll your own:

FIREWALL: iptables script using any one of a number of the ones
available. I like the one at
http://www.malibyte.net/iptables/scripts/fwscripts.html as a starting
point.

BANDWIDTH CAPPER: If you really just want to rate limit, iptables can
do that too. Otherwise, roll your own HTB or HFSC shaping script.

The tough part of shaping is that in order to be able to shape
everything, you must have one machine that sees all internet
connections so it can arbitrate who gets how much. I built a special
box with 3 NICs - one internal and two internet-facing. The internal
NIC shapes inbound and the external NICs shape outbound traffic.
http://www.lartc.org/
http://yesican.chsoft.biz/lartc/index.html
--
buck

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 02-20-2008, 06:41 AM
slacker
 
Posts: n/a
Default Re: Firewall + Bandwidth Throttle combo?

check out http://www.partydome.us/index.php?slackware for my slackware
10.1 config. included is a basic firewall (refuses all incomming
connections by default, you will have to add rulesets to allow
particular connections into services) and a traffic shaping rig built
using iptables/tc.

buck wrote:
> On 3 Mar 2005 07:01:00 -0800, macusr023@yahoo.com wrote:
>
>
>>Put together a Slack PC with several NICs to use as a router/switch.
>>Need both a firewall and bandwidth capper (have both separately). Has
>>anyone heard of a combo package? Searched sourceforge and google but
>>only came up with high end commercial products.
>>
>>If not, I'll go ahead with both ... Thanks in advance

>
>
> Don't know of any package, but if you could configure a box with
> "several" NICs you should be able to roll your own:
>
> FIREWALL: iptables script using any one of a number of the ones
> available. I like the one at
> http://www.malibyte.net/iptables/scripts/fwscripts.html as a starting
> point.
>
> BANDWIDTH CAPPER: If you really just want to rate limit, iptables can
> do that too. Otherwise, roll your own HTB or HFSC shaping script.
>
> The tough part of shaping is that in order to be able to shape
> everything, you must have one machine that sees all internet
> connections so it can arbitrate who gets how much. I built a special
> box with 3 NICs - one internal and two internet-facing. The internal
> NIC shapes inbound and the external NICs shape outbound traffic.
> http://www.lartc.org/
> http://yesican.chsoft.biz/lartc/index.html
> --
> buck
>

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 02-20-2008, 06:53 AM
Jack S. Lai
 
Posts: n/a
Default Re: Firewall + Bandwidth Throttle combo?

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

macusr023@yahoo.com wrote:

> Put together a Slack PC with several NICs to use as a router/switch.
> Need both a firewall and bandwidth capper (have both separately). Has
> anyone heard of a combo package? Searched sourceforge and google but
> only came up with high end commercial products.
>
> If not, I'll go ahead with both ... Thanks in advance

How about http://l7-filter.sourceforge.net/ for shaping with an iptables
firewall? Works great for me... but... they are trying to fix a memory leak
right at the moment.
- --
Slackware Tips & Tricks - http://members.cox.net/laitcg/slack.htm
P3Scan - Transparent POP3 virus/spam/mime/html scanning proxy:
http://p3scan.sourceforge.net
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.9.15 (GNU/Linux)

iD8DBQFCM+ur9/VKdZrnv3YRAttZAJ4sZZVKZyKrleeRtmhpdFm8ePV81QCfcf1+
dY5/6GREiRsFgdXUzikn9/w=
=S5o5
-----END PGP SIGNATURE-----
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT. The time now is 05:45 AM.


Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.2.0
www.UnixAdminTalk.com