Book Image

Configuring IPCop Firewalls: Closing Borders with Open Source

Book Image

Configuring IPCop Firewalls: Closing Borders with Open Source

Overview of this book

IPCop is a powerful, open source, Linux based firewall distribution for primarily Small Office Or Home (SOHO) networks, although it can be used in larger networks. It provides most of the features that you would expect a modern firewall to have, and what is most important is that it sets this all up for you in a highly automated and simplified way. This book is an easy introduction to this popular application. After introducing and explaining the foundations of firewalling and networking and why they're important, the book moves on to cover using IPCop, from installing it, through configuring it, to more advanced features, such as configuring IPCop to work as an IDS, VPN and using it for bandwidth management. While providing necessary theoretical background, the book takes a practical approach, presenting sample configurations for home users, small businesses, and large businesses. The book contains plenty of illustrative examples.
Table of Contents (16 chapters)
Configuring IPCop Firewalls
Credits
About the Authors
About the Reviewers
Preface
7
Virtual Private Networks
11
IPCop Support

Summary


We have seen that IPCop can be more than just a simple NAT firewall. It can handle multiple network zones and treat each of these independently. We can have real control over how these network segments can communicate with each other. A firewall can do much more than just filter—it can control, monitor, and report on the network's status giving us a good overall view of how our network is functioning, and IPCop can fulfill these requirements.

We have also seen IPCop as a network appliance similar to the expensive commercial offerings from many vendors. In this respect IPCop can handle advanced firewalling with some application-level or layer-seven filtering. We discussed this earlier and IPCop's layer-seven shortcomings. We now see how we can address this and any other problems to create a truly useful and powerful perimeter device.

We looked at the various addons available for IPCop and had a fairly detailed look at some of the most commonly used ones and the useful options available...