Top Banner
Unified Threat Management Systems (UTMS), Open Source Routers and Firewalls Tim Hooks Scott Rolf
31

Unified Threat Management Systems (UTMS), Open Source ...ilta.personifycloud.com/.../683/UnifiedThreatManagementSystems.pdf · Unified Threat Management Systems (UTMS), Open Source

Oct 28, 2018

Download

Documents

hoangque
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Unified Threat Management Systems (UTMS), Open Source ...ilta.personifycloud.com/.../683/UnifiedThreatManagementSystems.pdf · Unified Threat Management Systems (UTMS), Open Source

Unified Threat Management Systems (UTMS), Open Source Routers and Firewalls

Tim HooksScott Rolf

Page 2: Unified Threat Management Systems (UTMS), Open Source ...ilta.personifycloud.com/.../683/UnifiedThreatManagementSystems.pdf · Unified Threat Management Systems (UTMS), Open Source

Session Overview

The Linux Kernel is particularly adept at routing IP traffic and lends itself for use as the operating system for building not only your own router, but also routers that include firewalls and intrusion detection. Performance of these systems often outstrips that of proprietary products. Well-known packages include Astaro, Untangle, pfSense and IPCop.

Page 3: Unified Threat Management Systems (UTMS), Open Source ...ilta.personifycloud.com/.../683/UnifiedThreatManagementSystems.pdf · Unified Threat Management Systems (UTMS), Open Source

Untangle www.untangle.com

Included Free• Web Filter • Virus Blocker • Spam Blocker • Ad Blocker• Attack Blocker • Phish Blocker • Spyware Blocker • Firewall • Routing & QoS • Intrusion Prevention • Protocol Control • OpenVPN • Reports

Available for Fee• Live Support • eSoft Web Filter• Kaspersky Virus Blocker• Commtouch Spam Booster• WAN Balancer• WAN Failover• Policy Manager• AD Connector • PC Remote• Remote Access Portal• Branding Manager

Page 4: Unified Threat Management Systems (UTMS), Open Source ...ilta.personifycloud.com/.../683/UnifiedThreatManagementSystems.pdf · Unified Threat Management Systems (UTMS), Open Source

Untangle Deployment Options

• Router: Dedicated server that performs routing & firewall services

• Transparent Bridge: Dedicated server that drops seamlessly behind existing routers & firewalls

• Re-Router™: Adds network-wide protection while running on an existing desktop (runs on Windows)

• Runs on bare-metal install, or on Windows XP, or in VMware.

Page 5: Unified Threat Management Systems (UTMS), Open Source ...ilta.personifycloud.com/.../683/UnifiedThreatManagementSystems.pdf · Unified Threat Management Systems (UTMS), Open Source

Untangle Pro and Cons

PROS• Cost• Commercially

Support• Serves multiple

functions

CONS• Cost – not free!• Supports limited

number of NICS/networks

Page 6: Unified Threat Management Systems (UTMS), Open Source ...ilta.personifycloud.com/.../683/UnifiedThreatManagementSystems.pdf · Unified Threat Management Systems (UTMS), Open Source

Questions on Untangle?

Give it a try, you can build a box in about 20 minutes.

Page 7: Unified Threat Management Systems (UTMS), Open Source ...ilta.personifycloud.com/.../683/UnifiedThreatManagementSystems.pdf · Unified Threat Management Systems (UTMS), Open Source

IPCop www.ipcop.orgThe Bad Packets Stop Here.

Now we’re talking, think of IPCop as free replacement for your Cisco PIX (just add your own standard PC).

There are plenty of add-ons for this product also:

•URL filter with predefined categories

•Advanced Proxy

•OpenVPN

•ClamAV

•Update Accelerator for Windows Update caching

•BOT – Blockout all Traffic – used to specify which ports and addresses can be used for outgoing traffic

Page 8: Unified Threat Management Systems (UTMS), Open Source ...ilta.personifycloud.com/.../683/UnifiedThreatManagementSystems.pdf · Unified Threat Management Systems (UTMS), Open Source

IPCop Installation

• Again, very straight forward and quick.• Download an iso file, build cd, boot to cd

and it installs.• Pick add-ons, install and configure

Page 9: Unified Threat Management Systems (UTMS), Open Source ...ilta.personifycloud.com/.../683/UnifiedThreatManagementSystems.pdf · Unified Threat Management Systems (UTMS), Open Source

IPCop Pros and Cons

Pros• Free except for

hardware• Online community of

support• Continually developed

and enhanced

Cons• Not much

commercially available support

• Must learn something about linux to use, not much, but at least a little

Page 10: Unified Threat Management Systems (UTMS), Open Source ...ilta.personifycloud.com/.../683/UnifiedThreatManagementSystems.pdf · Unified Threat Management Systems (UTMS), Open Source

Questions on IPCop?

Page 11: Unified Threat Management Systems (UTMS), Open Source ...ilta.personifycloud.com/.../683/UnifiedThreatManagementSystems.pdf · Unified Threat Management Systems (UTMS), Open Source

Astaro – www.astaro.com

• Solution based on open source software• Buy appliance or image and pick your own

hardware• Web filtering• Anti-virus• Very good failover capabilities built in• Price based on size of data pipes

Page 12: Unified Threat Management Systems (UTMS), Open Source ...ilta.personifycloud.com/.../683/UnifiedThreatManagementSystems.pdf · Unified Threat Management Systems (UTMS), Open Source

Questions on Astaro?

Page 13: Unified Threat Management Systems (UTMS), Open Source ...ilta.personifycloud.com/.../683/UnifiedThreatManagementSystems.pdf · Unified Threat Management Systems (UTMS), Open Source

pfSense

Page 14: Unified Threat Management Systems (UTMS), Open Source ...ilta.personifycloud.com/.../683/UnifiedThreatManagementSystems.pdf · Unified Threat Management Systems (UTMS), Open Source

pfSense in a nutshell

• open source firewall• based on FreeBSD and the pf firewall

(packet filter)• 3 Editions – LiveCD, Embedded & Full

install

Page 15: Unified Threat Management Systems (UTMS), Open Source ...ilta.personifycloud.com/.../683/UnifiedThreatManagementSystems.pdf · Unified Threat Management Systems (UTMS), Open Source

Deployment Types

• Boarder Firewall to the Internet• Internet Proxy• LAN Router• WAN Router• Packet Sniffer• DHCP Server• VPN Server

Makes a great firewall for your home or remote war room!!!

Page 16: Unified Threat Management Systems (UTMS), Open Source ...ilta.personifycloud.com/.../683/UnifiedThreatManagementSystems.pdf · Unified Threat Management Systems (UTMS), Open Source

Hardware

• 10-20Mbs -> 266 MHz CPU• 21-50Mbs -> 500MHz CPU• 201-500Mbps -> 2GHz w/ pci-x or –e nic• 501+Mbpz -> 3GHz CPU

Embedded version can run on Soekris, Nexcom, Hacom and Mini ITX hardware

Page 17: Unified Threat Management Systems (UTMS), Open Source ...ilta.personifycloud.com/.../683/UnifiedThreatManagementSystems.pdf · Unified Threat Management Systems (UTMS), Open Source

VPN Throughput

• 4Mb -> 256MHz• 10Mb -> 500MHz

Page 18: Unified Threat Management Systems (UTMS), Open Source ...ilta.personifycloud.com/.../683/UnifiedThreatManagementSystems.pdf · Unified Threat Management Systems (UTMS), Open Source

What makes it so special?

• Supports multiple Internet Connections• Captive Portal • Wake on LAN• Packet Sniffing• Statistical Graphing• Simplified ruleset due to use of aliases• It’s free!!! (and offers more then many

commercial firewall appliances)

Page 19: Unified Threat Management Systems (UTMS), Open Source ...ilta.personifycloud.com/.../683/UnifiedThreatManagementSystems.pdf · Unified Threat Management Systems (UTMS), Open Source

What else can it do?

• Add on packages are being developed all the time.Automated backups Avahi (think Bonjour)

FreeSwitch VOIP antivirus proxy

IGMP Proxy Squid

Nagios client BGP

Radius support OpenVPN support

Instant Messaging Inspector cflow integration

SIP Proxy Intrusion detection

Stunnel spam removal

Page 20: Unified Threat Management Systems (UTMS), Open Source ...ilta.personifycloud.com/.../683/UnifiedThreatManagementSystems.pdf · Unified Threat Management Systems (UTMS), Open Source

How to do I set it up?

1. Find a computer with 2 network cards.2. Boot from the live cd and assign the

outside and inside interfaces.3. Your done.

Page 21: Unified Threat Management Systems (UTMS), Open Source ...ilta.personifycloud.com/.../683/UnifiedThreatManagementSystems.pdf · Unified Threat Management Systems (UTMS), Open Source

System Menu

Page 22: Unified Threat Management Systems (UTMS), Open Source ...ilta.personifycloud.com/.../683/UnifiedThreatManagementSystems.pdf · Unified Threat Management Systems (UTMS), Open Source

Interfaces Menu

Page 23: Unified Threat Management Systems (UTMS), Open Source ...ilta.personifycloud.com/.../683/UnifiedThreatManagementSystems.pdf · Unified Threat Management Systems (UTMS), Open Source

Firewall Menu

Page 24: Unified Threat Management Systems (UTMS), Open Source ...ilta.personifycloud.com/.../683/UnifiedThreatManagementSystems.pdf · Unified Threat Management Systems (UTMS), Open Source

Services Menu

Page 25: Unified Threat Management Systems (UTMS), Open Source ...ilta.personifycloud.com/.../683/UnifiedThreatManagementSystems.pdf · Unified Threat Management Systems (UTMS), Open Source

VPN Menu

Page 26: Unified Threat Management Systems (UTMS), Open Source ...ilta.personifycloud.com/.../683/UnifiedThreatManagementSystems.pdf · Unified Threat Management Systems (UTMS), Open Source

Status Menu

Page 27: Unified Threat Management Systems (UTMS), Open Source ...ilta.personifycloud.com/.../683/UnifiedThreatManagementSystems.pdf · Unified Threat Management Systems (UTMS), Open Source

Diagnostics Menu

Page 28: Unified Threat Management Systems (UTMS), Open Source ...ilta.personifycloud.com/.../683/UnifiedThreatManagementSystems.pdf · Unified Threat Management Systems (UTMS), Open Source

NAT Outbound

Page 29: Unified Threat Management Systems (UTMS), Open Source ...ilta.personifycloud.com/.../683/UnifiedThreatManagementSystems.pdf · Unified Threat Management Systems (UTMS), Open Source

RRD Graphs

Page 30: Unified Threat Management Systems (UTMS), Open Source ...ilta.personifycloud.com/.../683/UnifiedThreatManagementSystems.pdf · Unified Threat Management Systems (UTMS), Open Source

Check it out at www.pfsense.com

Page 31: Unified Threat Management Systems (UTMS), Open Source ...ilta.personifycloud.com/.../683/UnifiedThreatManagementSystems.pdf · Unified Threat Management Systems (UTMS), Open Source

Questions on pfSense?

Other questions? Comments?

Thanks for attending.