bgSEC would like to announce the distribution of bastion-firewall under
the GPL license. bastion-firewall is a Netfilter and Iptables based
firewall that can be configured with plain text configuration files and
can be used as a normal firewall or as a firewall script generator. It
can generate graphical statistics using rrdtool that can be viewed in a
generated web page that includes the graphics for the traffic in the
interfaces and for the rules that we can specify. It's integrated with
the snort-inline IPS and can pass the traffic to this IPS so it can
decide whether accept or deny the traffic.
It's main characteristics are:
* Written in Spanish and traduced to English, documentation included.
bastion-firewall has been developed at Spain
* It includes all kinds of documentation, included some tutorials
(only in spanish) for the use and administration of the firewall
* Configuration files totally commented with a lot of hel for an easy
firewall configuration
* Developed in bash and C languages. 25000 lines of code that the user
can modify in an easy way
* It allows any number of inner and outer interfaces
* It can generate a web page with statistics of the traffic in the
firewall and statistics of the rules using rrdtool
* It generates a script with all the commands the firewall executes
when it's loaded. This script can be used as an independent firewall
* Integrated with the snort-inline IPS using the QUEUE facility
* It allows us to use blacklists and whitelists for IPs and MAC addresses
* It can be managed with a group of command to acomplish the more
commmon administration tasks
* MD5 based cache system to speed up the firewall loading when the
firewall configuration have not changed
* It allows us to control the traffic with the configuration files
using flows and also using lists with more specific rules
* It provides all kinds of facilities to do NAT, SNAT, DNAT and REDIRECT
* Activates all the kernel protections and prevents against denial of
service attacks, spoofing, fragmentation and others
* It includes a group of templates for the more common configurations
that allows the administrator to configurate the firewall easily
* It allows the use of IP lists and IP ranks as if they were IP
addresses,just including them in the configuration files
* Makes extensive use of network and services groups so you can
configure the firewall changing a minimum of variables in the
configuration files
* It is distributed in rpm, deb and tar.bz2 packages. Source code
available
bastion-firewall has a lot of other characteristics you can consult in
the documentation and in the configuration files.
To download bastion-firewall you can use the next facilities:
The main web site for bastion firewall allows the downloading of all the
files of bastion-firewall and it's hosted at bgSEC in the next address:
http://www.bgsec.com (Downloads section)
The web page of the project at Freshmeat is:
http://freshmeat.net/projects/bastion-firewall
The pages for the project at Sourceforge are:
Project summary page and development facilities:
http://sourceforge.net/projects/bastionfirewall
Project web page:
http://bastionfirewall.sourceforge.net
Project files:
http://sourceforge.net/project/showf...roup_id=116369
To collaborate in the project you can use the facilities at Sourceforge
visiting the project summary web page or you can follow the next link to
subscribe to the bastion-firewall mailing list at bgSEC:
http://list.bgsec.com
We hope bastion-firewall will be useful for the end user and also to the
production systems administrations.
--
Jose Maria Lopez Hernandez
Director Tecnico de bgSEC
(E-Mail Removed)
bgSEC Seguridad y Consultoria de Sistemas Informaticos
http://www.bgsec.com
ESPAÑA
The only people for me are the mad ones -- the ones who are mad to live,
mad to talk, mad to be saved, desirous of everything at the same time,
the ones who never yawn or say a commonplace thing, but burn, burn, burn
like fabulous yellow Roman candles.
-- Jack Kerouac, "On the Road"