firewalls opensource

78
Eduardo Coelho http:// coelho.ithub.com.br Firewalls Opensource

Upload: eduardo-coelho

Post on 30-May-2015

4.038 views

Category:

Technology


2 download

DESCRIPTION

Uma visão técnica de soluções de proteção em código aberto

TRANSCRIPT

Page 1: Firewalls Opensource

Eduardo Coelho

http://coelho.ithub.com.br

Firewalls Opensource

Page 2: Firewalls Opensource

Eduardo Coelho

Firewalls Opensourceuma visão técnica de soluções de proteção em código aberto

Page 3: Firewalls Opensource

Porque isso muda tudoBSD license x GPL

Licenças opensource

Page 4: Firewalls Opensource

Firewall Opensource

Agora Realmente

Page 5: Firewalls Opensource

Linux FreeBSDOpenBSD

Plataformas

Page 6: Firewalls Opensource

Netfiler/Iptables (+IProute2+HTB/CBQ) IPFWPF

Kernel-level firewalls

Page 7: Firewalls Opensource
Page 8: Firewalls Opensource
Page 9: Firewalls Opensource
Page 10: Firewalls Opensource

Absurdamente rápidosProcessam tráfego de redeBy default já rodam no kernel Features incluem: Statefull inspectionQoS/Priorization Static RoutingDynamic Routing*

Kernel-level firewalls

Page 11: Firewalls Opensource

Fwbuilder Shorewall

Assistentes de Configuração

Page 12: Firewalls Opensource
Page 13: Firewalls Opensource

Instalação no Debian:#aptitude install shorewall

Quick Start Guide:http://www.shorewall.net/ shorewall_quickstart_guide.htm

Shorewall

Page 14: Firewalls Opensource
Page 15: Firewalls Opensource

Instalação no Debian:#aptitude install fwbuilderOBS: requer X instalado

Instalação Windows (comercial)http://www.fwbuilder.com17 MB downloadNext->Next->Finish

Quick Start Guide:http://www.fwbuilder.org/ 4.0/docs/users_guide/ gettingstarted.html

Fwbuilder

Page 16: Firewalls Opensource
Page 17: Firewalls Opensource
Page 18: Firewalls Opensource

Licença dupla GPL+Comercial

Versão Windows empacotada somente na comercial

Suporte diversos firewalls, incluindo Netfilter, IPFW, PF

GUI

Fwbuilder

Page 19: Firewalls Opensource

SquidDansguardian

Content Filters

Page 20: Firewalls Opensource

Instalação no Debian:#aptitude install squid

É um Proxy HTTP (Acelerador)

Possibilidade de Gerar Relatórios (SARG)

Config Examples:http://wiki.squid-cache.org/ ConfigExamples/

Squid

Page 21: Firewalls Opensource
Page 22: Firewalls Opensource

Faz uso intenso de RAM, HD e CPU e na maioria dos casos requerer um hardware de PC/Server

Possui uma grande comunidade de usuários

Curva de aprendizado lenta

Permite controle de banda simples via delay_pools (controle de taxa de transferência para download)

Pode ser usado como Reverse Proxy (Acelerador de Aplicação)

Squid

Page 23: Firewalls Opensource

Instalação no Debian:#aptitude install dansguardian

Processa 100% do conteúdo via String Match

Ubuntu Config Example:http://www.pilpi.net/journal/ 2006/03/setting-up- dansguardian-on-a-single-home- pc-running-ubuntu/

Dan’s Guardian

Page 24: Firewalls Opensource
Page 25: Firewalls Opensource

Não faz cache

É usado normalmente em conjunto com o squid

Possui uma grande comunidade de usuários

É usado em milhares de escolas, bibliotecas e faculdades para filtragem de conteúdo web

Dan’s Guardian

Page 26: Firewalls Opensource

VyattaPfsenseUntangleMonowall SmoothwallZentyal IPCopEndianClearOSZeroshellProxmox

Distro

Page 27: Firewalls Opensource

PfsenseMonowall IPCopZeroshell

Community-Supported

Distros

Page 28: Firewalls Opensource

Administração WebPrincipais features Statefull firewallVPNTraffic ShappingDHCPDNS

ISO = 18MB (!)

Monowall

Page 29: Firewalls Opensource
Page 30: Firewalls Opensource
Page 31: Firewalls Opensource
Page 32: Firewalls Opensource

Administração WebPrincipais features Statefull firewallVPNTraffic ShappingDHCPDNS

ISO = 65MB

Pfsense

Page 33: Firewalls Opensource
Page 34: Firewalls Opensource
Page 35: Firewalls Opensource
Page 36: Firewalls Opensource

Administração Web Principais features Statefull firewall VPN Traffic Shapping DHCP DNS HTTP Proxy + Web antivirus LDAP SSL CA

VMware friendly ISO = 148MB

Zeroshell

Page 37: Firewalls Opensource
Page 38: Firewalls Opensource
Page 39: Firewalls Opensource
Page 40: Firewalls Opensource

Administração WebPrincipais features Statefull firewallVPNTraffic ShappingDHCPDNS

ISO = 51MB

IPCOP

Page 41: Firewalls Opensource
Page 42: Firewalls Opensource
Page 43: Firewalls Opensource
Page 44: Firewalls Opensource

VyattaUntangle SmoothwallZentyalEndianClearOSProxmox

CommecialSupported

Distros

Page 45: Firewalls Opensource

Antigo E-BOX Principais features

Statefull firewall VPN Traffic Shapping DHCP DNS LDAP HTTP Proxy IDS SSL CA Zarafa (groupware) Samba Duplicity (backup) Jabber Asterisk Postfix

ISO = 470MB

Zentyal

Page 46: Firewalls Opensource
Page 47: Firewalls Opensource
Page 48: Firewalls Opensource
Page 49: Firewalls Opensource

Principais features Statefull firewall VPN Traffic Shapping DHCP DNS LDAP HTTP Proxy SSL CA Postfix

ISO = 700MB

ClearOS

Page 50: Firewalls Opensource
Page 51: Firewalls Opensource
Page 52: Firewalls Opensource
Page 53: Firewalls Opensource

Mail Gateway

Principais features Statefull firewall VPN Traffic Shapping DHCP DNS LDAP SQL SSH

VMware friendly Suporte embutido para Kaspersky e Avira

ISO = 345MB

Proxmox

Page 54: Firewalls Opensource
Page 55: Firewalls Opensource
Page 56: Firewalls Opensource
Page 57: Firewalls Opensource

CLI e WebGUI Opção para gateway de alto desempenho Posiciona-se como alternativa opensource a

Cisco e Juniper Principais features

Statefull firewall VPN Traffic Shapping DHCP DNS LDAP QoS Bonding Load balancing Dynamic Routing

ISO = 164MB

Vyatta

Page 58: Firewalls Opensource
Page 59: Firewalls Opensource
Page 60: Firewalls Opensource
Page 61: Firewalls Opensource

Estrutura de pacotes grátis e pagos facilita o licenciamento

Principais features Statefull firewall VPN Traffic Shapping DHCP DNS LDAP HTTP Proxy IDS SSL CA Samba

ISO = 456MB

Untangle

Page 62: Firewalls Opensource
Page 63: Firewalls Opensource
Page 64: Firewalls Opensource
Page 65: Firewalls Opensource
Page 66: Firewalls Opensource

Principais features Statefull firewall VPN Traffic Shapping DHCP DNS LDAP HTTP Proxy IDS SSL CA Samba Asterisk Postfix

ISO = 78MB

Smoothwall

Page 67: Firewalls Opensource
Page 68: Firewalls Opensource
Page 69: Firewalls Opensource
Page 70: Firewalls Opensource

Principais features Statefull firewall VPN Traffic Shapping DHCP DNS LDAP HTTP Proxy IDS Samba Postfix

High availability NTLM SSO Hotspot

Hardware e Software Appliance

ISO = 130MB

Endian

Page 71: Firewalls Opensource
Page 72: Firewalls Opensource
Page 73: Firewalls Opensource
Page 74: Firewalls Opensource

OSSEC Snort SELinuxAppArmorTripwire Fakeroot

Virtualização

Security Tools

Page 75: Firewalls Opensource

http://coelho.ithub.com.br

Obrigado =)

Slides disponíveis no meu blog

Page 76: Firewalls Opensource

AprendaTI com a

Page 77: Firewalls Opensource
Page 78: Firewalls Opensource

Eventos em Outubro