Off Topic - Firewall / NAT / Proxy

Todd,

We have one(50) and have placed them in several customers as well. In every
case, after the install, there have been no internet based network threats
experienced at all. The only incident that has occurred happened due to a
corrupt file introduced on a floppy disk at one site.

Trust me...these devices rate an A+ on the Graver scale of threat
deterrence.

Michael

p.s. and, no, we are not a reseller...they're just that good.

-----Original Message-----
From: Todd Anderson [mailto:tanderson@...]
Sent: Friday, November 21, 2003 9:25 AM
To: 'vantage@yahoogroups.com'
Subject: RE: [Vantage] Off Topic - Firewall / NAT / Proxy

I've been reading white papers on the FortiGate products on and off for the
last few days.

Looks like very interesting technology and a somewhat unique angle on how to
handle viruses, VOIP through NAT, intrusion detection, and VPN ... all in
one box at a hard to beat price.

My thanks to Michael for the info.

Next question - who has these boxes actually installed ?

Thanks,

Todd Anderson

-----Original Message-----
From: Michael Barry [mailto:mbarry@...]
Sent: Tuesday, November 04, 2003 1:49 PM
To: vantage@yahoogroups.com
Subject: RE: [Vantage] Off Topic - Firewall / NAT / Proxy


Second that motion check out the following:

www.fortinet.com

How about unlimited user full real-time stateful packet inspection
firewall/intrusion detection/NAT/VPN/Traffic Shaping/Virus Scanning/DMZ/Push
and Pull definitions updates/and soon to add Spam Filtering - All for under
1k. Add to that the fact that setup takes all of two minutes and then it is
set and forget...

mjb





[Non-text portions of this message have been removed]


------------------------ Yahoo! Groups Sponsor ---------------------~--> Buy
Ink Cartridges or Refill Kits for your HP, Epson, Canon or Lexmark Printer
at MyInks.com. Free s/h on orders $50 or more to the US & Canada.
http://www.c1tracking.com/l.asp?cid=5511
http://us.click.yahoo.com/mOAaAA/3exGAA/qnsNAA/PhFolB/TM
---------------------------------------------------------------------~->

Useful links for the Yahoo!Groups Vantage Board are: ( Note: You must have
already linked your email address to a yahoo id to enable access. )
(1) To access the Files Section of our Yahoo!Group for Report Builder and
Crystal Reports and other 'goodies', please goto:
http://groups.yahoo.com/group/vantage/files/.
(2) To search through old msg's goto:
http://groups.yahoo.com/group/vantage/messages
(3) To view links to Vendors that provide Vantage services goto:
http://groups.yahoo.com/group/vantage/links

Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/
I've been using MS Proxy Server 2.0 for years. Having some problems with
compatability with Win2k and AD.
Does anyone have experience with Linux based Firewalls and Proxy/NAT?
What's the best way to go. With tight budgets the MS Internet Acceleration
and Security server is a little bit high.

Thanks
Bob Bruton
Entek Corp.


[Non-text portions of this message have been removed]
Bob,

You have lots of options. Which combination you pick will depend on
your authentication scheme and caching requirements:

iptables (www.netfilter.org) is definitely what you will be using for
NAT. It can also do the proxy work, but you may need to utilize some
other packages to get your authentication how you like it. It is
kernel-level so it is hella fast.

Squid (www.squid.org) is your answer to proxy caching (Internet
Acceleration. It will also be necessary to facilitate content
restriction.

Samba may be needed if you are trying to replicate the NTLM
authentication that MS Proxy server does. Otherwise (AFAIK) if you are
implementing access control based on username / password, the users will
get a login box when they open up their web browsers.

I can shoot you over some scripts / config files if you like,
AE

On Tue, 2003-11-04 at 10:45, Robert Bruton wrote:

> I've been using MS Proxy Server 2.0 for years. Having some problems with
> compatability with Win2k and AD.
> Does anyone have experience with Linux based Firewalls and Proxy/NAT?
> What's the best way to go. With tight budgets the MS Internet Acceleration
> and Security server is a little bit high.
>
> Thanks
> Bob Bruton
> Entek Corp.
>




[Non-text portions of this message have been removed]
A tip that I got from another on the list some time ago.
www.kyzo.com has a couple of great Linux products that are great for those
without any previous Linux knowledge.
Free trials for each product are available, and I have to say...if you are
new to Linux, will sell you on the product.

Good luck,
Aaron Hoyt
Design Standards

-----Original Message-----
From: Adam Ellis [mailto:AELinuxGuy@...]
Sent: Tuesday, November 04, 2003 11:15 AM
To: vantage@yahoogroups.com
Subject: Re: [Vantage] Off Topic - Firewall / NAT / Proxy


Bob,

You have lots of options. Which combination you pick will depend on
your authentication scheme and caching requirements:

iptables (www.netfilter.org) is definitely what you will be using for
NAT. It can also do the proxy work, but you may need to utilize some
other packages to get your authentication how you like it. It is
kernel-level so it is hella fast.

Squid (www.squid.org) is your answer to proxy caching (Internet
Acceleration. It will also be necessary to facilitate content
restriction.

Samba may be needed if you are trying to replicate the NTLM
authentication that MS Proxy server does. Otherwise (AFAIK) if you are
implementing access control based on username / password, the users will
get a login box when they open up their web browsers.

I can shoot you over some scripts / config files if you like,
AE

On Tue, 2003-11-04 at 10:45, Robert Bruton wrote:

> I've been using MS Proxy Server 2.0 for years. Having some problems with
> compatability with Win2k and AD.
> Does anyone have experience with Linux based Firewalls and Proxy/NAT?
> What's the best way to go. With tight budgets the MS Internet
Acceleration
> and Security server is a little bit high.
>
> Thanks
> Bob Bruton
> Entek Corp.
>




[Non-text portions of this message have been removed]



Useful links for the Yahoo!Groups Vantage Board are: ( Note: You must have
already linked your email address to a yahoo id to enable access. )
(1) To access the Files Section of our Yahoo!Group for Report Builder and
Crystal Reports and other 'goodies', please goto:
http://groups.yahoo.com/group/vantage/files/.
(2) To search through old msg's goto:
http://groups.yahoo.com/group/vantage/messages
(3) To view links to Vendors that provide Vantage services goto:
http://groups.yahoo.com/group/vantage/links

Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/
Great! I haven't ventured into the Linux world yet. A little bit envious of
the F R E E aspects.

-----Original Message-----
From: Aaron Hoyt [mailto:aaron.hoyt@...]
Sent: Tuesday, November 04, 2003 10:56 AM
To: vantage@yahoogroups.com
Subject: RE: [Vantage] Off Topic - Firewall / NAT / Proxy


A tip that I got from another on the list some time ago.
www.kyzo.com has a couple of great Linux products that are great for those
without any previous Linux knowledge.
Free trials for each product are available, and I have to say...if you are
new to Linux, will sell you on the product.

Good luck,
Aaron Hoyt
Design Standards

-----Original Message-----
From: Adam Ellis [mailto:AELinuxGuy@...]
Sent: Tuesday, November 04, 2003 11:15 AM
To: vantage@yahoogroups.com
Subject: Re: [Vantage] Off Topic - Firewall / NAT / Proxy


Bob,

You have lots of options. Which combination you pick will depend on
your authentication scheme and caching requirements:

iptables (www.netfilter.org) is definitely what you will be using for
NAT. It can also do the proxy work, but you may need to utilize some
other packages to get your authentication how you like it. It is
kernel-level so it is hella fast.

Squid (www.squid.org) is your answer to proxy caching (Internet
Acceleration. It will also be necessary to facilitate content
restriction.

Samba may be needed if you are trying to replicate the NTLM
authentication that MS Proxy server does. Otherwise (AFAIK) if you are
implementing access control based on username / password, the users will
get a login box when they open up their web browsers.

I can shoot you over some scripts / config files if you like,
AE

On Tue, 2003-11-04 at 10:45, Robert Bruton wrote:

> I've been using MS Proxy Server 2.0 for years. Having some problems with
> compatability with Win2k and AD.
> Does anyone have experience with Linux based Firewalls and Proxy/NAT?
> What's the best way to go. With tight budgets the MS Internet
Acceleration
> and Security server is a little bit high.
>
> Thanks
> Bob Bruton
> Entek Corp.
>




[Non-text portions of this message have been removed]



Useful links for the Yahoo!Groups Vantage Board are: ( Note: You must have
already linked your email address to a yahoo id to enable access. )
(1) To access the Files Section of our Yahoo!Group for Report Builder and
Crystal Reports and other 'goodies', please goto:
http://groups.yahoo.com/group/vantage/files/.
<http://groups.yahoo.com/group/vantage/files/.>
(2) To search through old msg's goto:
http://groups.yahoo.com/group/vantage/messages
<http://groups.yahoo.com/group/vantage/messages>
(3) To view links to Vendors that provide Vantage services goto:
http://groups.yahoo.com/group/vantage/links
<http://groups.yahoo.com/group/vantage/links>

Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/
<http://docs.yahoo.com/info/terms/>






Yahoo! Groups Sponsor

ADVERTISEMENT

<http://rd.yahoo.com/M=267637.4116730.5333196.1261774/D=egroupweb/S=17050071
83:HM/A=1754451/R=0/SIG=11tm86fb5/*http://www.netflix.com/Default?mqso=60178
323&partid=4116730> click here

<http://us.adserver.yahoo.com/l?M=267637.4116730.5333196.1261774/D=egroupmai
l/S=:HM/A=1754451/rand=547257492>

Useful links for the Yahoo!Groups Vantage Board are: ( Note: You must have
already linked your email address to a yahoo id to enable access. )
(1) To access the Files Section of our Yahoo!Group for Report Builder and
Crystal Reports and other 'goodies', please goto:
http://groups.yahoo.com/group/vantage/files/.
<http://groups.yahoo.com/group/vantage/files/.>
(2) To search through old msg's goto:
http://groups.yahoo.com/group/vantage/messages
<http://groups.yahoo.com/group/vantage/messages>
(3) To view links to Vendors that provide Vantage services goto:
http://groups.yahoo.com/group/vantage/links
<http://groups.yahoo.com/group/vantage/links>

Your use of Yahoo! Groups is subject to the Yahoo! Terms of Service
<http://docs.yahoo.com/info/terms/> .




[Non-text portions of this message have been removed]
I have to agree with Aaron. We specifically use Kyzo's Net-Inter-net
product and it is excellent. Ten percent the cost of Exchange at 25 users.
Though N-I-N allows unlimited users and we currently run it on an old PII
with 128Mb of Ram. Plus, it took longer for the Sprint tech to confirm our
new DSL was working than to reconfig the N-I-N from dial-up to the DSL
service.
David Gartner
EPG Companies Inc.


-----Original Message-----
From: Robert Bruton [mailto:bob@...]
Sent: Tuesday, November 04, 2003 11:23 AM
To: vantage@yahoogroups.com
Subject: RE: [Vantage] Off Topic - Firewall / NAT / Proxy



Great! I haven't ventured into the Linux world yet. A little bit envious
of
the F R E E aspects.

-----Original Message-----
From: Aaron Hoyt [mailto:aaron.hoyt@...]
Sent: Tuesday, November 04, 2003 10:56 AM
To: vantage@yahoogroups.com
Subject: RE: [Vantage] Off Topic - Firewall / NAT / Proxy


A tip that I got from another on the list some time ago.
www.kyzo.com has a couple of great Linux products that are great for those
without any previous Linux knowledge.
Free trials for each product are available, and I have to say...if you are
new to Linux, will sell you on the product.

Good luck,
Aaron Hoyt
Design Standards

-----Original Message-----
From: Adam Ellis [mailto:AELinuxGuy@...]
Sent: Tuesday, November 04, 2003 11:15 AM
To: vantage@yahoogroups.com
Subject: Re: [Vantage] Off Topic - Firewall / NAT / Proxy


Bob,

You have lots of options. Which combination you pick will depend on
your authentication scheme and caching requirements:

iptables (www.netfilter.org) is definitely what you will be using for
NAT. It can also do the proxy work, but you may need to utilize some
other packages to get your authentication how you like it. It is
kernel-level so it is hella fast.

Squid (www.squid.org) is your answer to proxy caching (Internet
Acceleration. It will also be necessary to facilitate content
restriction.

Samba may be needed if you are trying to replicate the NTLM
authentication that MS Proxy server does. Otherwise (AFAIK) if you are
implementing access control based on username / password, the users will
get a login box when they open up their web browsers.

I can shoot you over some scripts / config files if you like,
AE

On Tue, 2003-11-04 at 10:45, Robert Bruton wrote:

> I've been using MS Proxy Server 2.0 for years. Having some problems
with
> compatability with Win2k and AD.
> Does anyone have experience with Linux based Firewalls and Proxy/NAT?
> What's the best way to go. With tight budgets the MS Internet
Acceleration
> and Security server is a little bit high.
>
> Thanks
> Bob Bruton
> Entek Corp.
>




[Non-text portions of this message have been removed]



Useful links for the Yahoo!Groups Vantage Board are: ( Note: You must
have
already linked your email address to a yahoo id to enable access. )
(1) To access the Files Section of our Yahoo!Group for Report Builder and
Crystal Reports and other 'goodies', please goto:
http://groups.yahoo.com/group/vantage/files/.
<http://groups.yahoo.com/group/vantage/files/.>
(2) To search through old msg's goto:
http://groups.yahoo.com/group/vantage/messages
<http://groups.yahoo.com/group/vantage/messages>
(3) To view links to Vendors that provide Vantage services goto:
http://groups.yahoo.com/group/vantage/links
<http://groups.yahoo.com/group/vantage/links>

Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/
<http://docs.yahoo.com/info/terms/>






Yahoo! Groups Sponsor

ADVERTISEMENT


<http://rd.yahoo.com/M=267637.4116730.5333196.1261774/D=egroupweb/S=17050071

83:HM/A=1754451/R=0/SIG=11tm86fb5/*http://www.netflix.com/Default?mqso=60178
323&partid=4116730> click here


<http://us.adserver.yahoo.com/l?M=267637.4116730.5333196.1261774/D=egroupmai

l/S=:HM/A=1754451/rand=547257492>

Useful links for the Yahoo!Groups Vantage Board are: ( Note: You must
have
already linked your email address to a yahoo id to enable access. )
(1) To access the Files Section of our Yahoo!Group for Report Builder and
Crystal Reports and other 'goodies', please goto:
http://groups.yahoo.com/group/vantage/files/.
<http://groups.yahoo.com/group/vantage/files/.>
(2) To search through old msg's goto:
http://groups.yahoo.com/group/vantage/messages
<http://groups.yahoo.com/group/vantage/messages>
(3) To view links to Vendors that provide Vantage services goto:
http://groups.yahoo.com/group/vantage/links
<http://groups.yahoo.com/group/vantage/links>

Your use of Yahoo! Groups is subject to the Yahoo! Terms of Service
<http://docs.yahoo.com/info/terms/> .




[Non-text portions of this message have been removed]


Yahoo! Groups Sponsor
ADVERTISEMENT




Useful links for the Yahoo!Groups Vantage Board are: ( Note: You must
have already linked your email address to a yahoo id to enable access. )
(1) To access the Files Section of our Yahoo!Group for Report Builder and
Crystal Reports and other 'goodies', please goto:
http://groups.yahoo.com/group/vantage/files/.
(2) To search through old msg's goto:
http://groups.yahoo.com/group/vantage/messages
(3) To view links to Vendors that provide Vantage services goto:
http://groups.yahoo.com/group/vantage/links

Your use of Yahoo! Groups is subject to the Yahoo! Terms of Service.


[Non-text portions of this message have been removed]
Second that motion check out the following:

www.fortinet.com

How about unlimited user full real-time stateful packet inspection
firewall/intrusion detection/NAT/VPN/Traffic Shaping/Virus Scanning/DMZ/Push
and Pull definitions updates/and soon to add Spam Filtering - All for under
1k. Add to that the fact that setup takes all of two minutes and then it is
set and forget...

mjb

-----Original Message-----
From: Ordway, Bruce [mailto:bruceo@...]
Sent: Tuesday, November 04, 2003 9:36 AM
To: vantage@yahoogroups.com
Subject: RE: [Vantage] Off Topic - Firewall / NAT / Proxy

Linux firewalls are pretty easy to set up with IPTABLES.
A guy can make a career out of rule building though.
I prefer NAT, but I know for a fact that it broke ClienteleNet.
Maybe Proxy is better because of this, but I'm not sure.
I'd look at some firewall appliances these days.
They're getting pretty inexpensive.

-----Original Message-----
From: Robert Bruton [mailto:bob@...]
Sent: Tue 11/4/2003 9:45 AM
To: vantage@yahoogroups.com
Cc:
Subject: [Vantage] Off Topic - Firewall / NAT / Proxy



I've been using MS Proxy Server 2.0 for years. Having some problems
with
compatability with Win2k and AD.
Does anyone have experience with Linux based Firewalls and
Proxy/NAT?
What's the best way to go. With tight budgets the MS Internet
Acceleration
and Security server is a little bit high.

Thanks
Bob Bruton
Entek Corp.


[Non-text portions of this message have been removed]


------------------------ Yahoo! Groups Sponsor

Useful links for the Yahoo!Groups Vantage Board are: ( Note: You
must have already linked your email address to a yahoo id to enable access.
)
(1) To access the Files Section of our Yahoo!Group for Report
Builder and Crystal Reports and other 'goodies', please goto:
http://groups.yahoo.com/group/vantage/files/.
(2) To search through old msg's goto:
http://groups.yahoo.com/group/vantage/messages
(3) To view links to Vendors that provide Vantage services goto:
http://groups.yahoo.com/group/vantage/links

Your use of Yahoo! Groups is subject to
http://docs.yahoo.com/info/terms/






[Non-text portions of this message have been removed]


------------------------ Yahoo! Groups Sponsor ---------------------~--> Buy
Ink Cartridges or Refill Kits for your HP, Epson, Canon or Lexmark Printer
at MyInks.com. Free s/h on orders $50 or more to the US & Canada.
http://www.c1tracking.com/l.asp?cid=5511
http://us.click.yahoo.com/mOAaAA/3exGAA/qnsNAA/PhFolB/TM
---------------------------------------------------------------------~->

Useful links for the Yahoo!Groups Vantage Board are: ( Note: You must have
already linked your email address to a yahoo id to enable access. )
(1) To access the Files Section of our Yahoo!Group for Report Builder and
Crystal Reports and other 'goodies', please goto:
http://groups.yahoo.com/group/vantage/files/.
(2) To search through old msg's goto:
http://groups.yahoo.com/group/vantage/messages
(3) To view links to Vendors that provide Vantage services goto:
http://groups.yahoo.com/group/vantage/links

Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/
We have just gone thru the same thing.
We have just replaced an old Proxy 2.0 with a Linux (Mandrake 9.1) squid server.
I didnt have a lot of experience with Linux before this and I found it didnt take too long to get it all setup. So much so that I also added Access monitor and content filtering on the same setup.

If money is tight I would suggest looking into linux for sure.
The firewall side of things im not sure on as I installed a hardware firewall (middle of the range in price $800 Aus $)

Good luck

Michael Cavanagh

-----Original Message-----
From: Robert Bruton [mailto:bob@...]
Sent: Wednesday, 5 November 2003 2:15 AM
To: vantage@yahoogroups.com
Subject: [Vantage] Off Topic - Firewall / NAT / Proxy


I've been using MS Proxy Server 2.0 for years. Having some problems with
compatability with Win2k and AD.
Does anyone have experience with Linux based Firewalls and Proxy/NAT?
What's the best way to go. With tight budgets the MS Internet Acceleration
and Security server is a little bit high.

Thanks
Bob Bruton
Entek Corp.


[Non-text portions of this message have been removed]



Yahoo! Groups Sponsor

ADVERTISEMENT
<http://rd.yahoo.com/M=267637.4116732.5333197.1261774/D=egroupweb/S=1705007183:HM/A=1754452/R=0/SIG=11tpoan5t/*http://www.netflix.com/Default?mqso=60178324&partid=4116732> click here
<http://us.adserver.yahoo.com/l?M=267637.4116732.5333197.1261774/D=egroupmail/S=:HM/A=1754452/rand=598043802>

Useful links for the Yahoo!Groups Vantage Board are: ( Note: You must have already linked your email address to a yahoo id to enable access. )
(1) To access the Files Section of our Yahoo!Group for Report Builder and Crystal Reports and other 'goodies', please goto: http://groups.yahoo.com/group/vantage/files/.
(2) To search through old msg's goto: http://groups.yahoo.com/group/vantage/messages
(3) To view links to Vendors that provide Vantage services goto: http://groups.yahoo.com/group/vantage/links

Your use of Yahoo! Groups is subject to the Yahoo! Terms of Service <http://docs.yahoo.com/info/terms/> .




[Non-text portions of this message have been removed]
I've been reading white papers on the FortiGate products on and off for the
last few days.

Looks like very interesting technology and a somewhat unique angle on how to
handle viruses, VOIP through NAT, intrusion detection, and VPN ... all in
one box at a hard to beat price.

My thanks to Michael for the info.

Next question - who has these boxes actually installed ?

Thanks,

Todd Anderson

-----Original Message-----
From: Michael Barry [mailto:mbarry@...]
Sent: Tuesday, November 04, 2003 1:49 PM
To: vantage@yahoogroups.com
Subject: RE: [Vantage] Off Topic - Firewall / NAT / Proxy


Second that motion check out the following:

www.fortinet.com

How about unlimited user full real-time stateful packet inspection
firewall/intrusion detection/NAT/VPN/Traffic Shaping/Virus Scanning/DMZ/Push
and Pull definitions updates/and soon to add Spam Filtering - All for under
1k. Add to that the fact that setup takes all of two minutes and then it is
set and forget...

mjb





[Non-text portions of this message have been removed]