You are not logged in.

#1 2009-01-28 12:03:35

albrow
Member
Registered: 2006-08-18
Posts: 9

SELinux on an Arch-based firewall - is it worth doing?

I'm building a 2-tier firewall system for work.  I'm currently working on the second tier and building it with Arch.  (Our parent company's IT department wanted me to use CentOS, but the router crashed every time I tried to boot the install CD... so I went back to what I know and love.)

I was just wondering if people thought that it was worth using SELinux on a firewall?  Also, has anyone had experience with SELinux?  If I do go down this path, it'll be the first time I've done it, so any advice will be gladly received!

Thanks
Alex

Offline

#2 2009-01-28 17:22:39

aglarond
Member
From: Texas, USA
Registered: 2008-11-20
Posts: 129

Re: SELinux on an Arch-based firewall - is it worth doing?

In general, I wouldn't think it would be worth it. SELinux is really great for access control when a lot of people are on one machine. Most firewalls are just used for passthrough so you'd have a lot of work in front of you for very little benefit.

I've never used Arch for a firewall, but I have a number of inside and outside firewalls running Gentoo without the SE extensions and I've never had a problem.

Just my opinion, though. There may be a good reason to do it that I haven't thought of.

-mS

Offline

#3 2009-01-31 23:57:33

stefanwilkens
Member
From: Enschede, the Netherlands
Registered: 2008-12-10
Posts: 624

Re: SELinux on an Arch-based firewall - is it worth doing?

not to bash arch, but have you looked at these:
http://distrowatch.com/dwres.php?resource=firewalls


Arch i686 on Phenom X4 | GTX760

Offline

#4 2009-02-01 00:10:16

aglarond
Member
From: Texas, USA
Registered: 2008-11-20
Posts: 129

Re: SELinux on an Arch-based firewall - is it worth doing?

stefanwilkens wrote:

not to bash arch, but have you looked at these:
http://distrowatch.com/dwres.php?resource=firewalls

On that note, I can personally recommend the Astaro Security Gateway. I use it at home for free and we pay for the extra VPN connections at work.

-mS

Offline

Board footer

Powered by FluxBB