System [home] [right] [e-mail] [system] [left]
 
 F I R E W A L L
Statistics
CPUIntel Pentium 2
SPEED300 MHz
MEMORY128Mb SDRAM
OSLinux [Slakware]
DVDSONY MULTI
VIDEON-Videa PCI
NETWORKNetGear FA311
3C509B
DRIVESIDE1    2Gb
SCSI 9Gb
MISCBT848 FGraber
ESS Sound
TA150M

Firewall is a hacked-together PC that does a little of everything. It acts as a firewall to prevent outsiders from getting into the LAN, does web page serving, and acts as the home security system.

The firewall side of things uses IpTables in Slackware (post-patch, so don't bother...) to route messages to the proper machines on the LAN. A special home-rolled version of Apachee provides a safe way to send out pages (without all the modules turned on). And the system acts as a transparent proxy and DNS cache (so basicly it's a D-Link router so far. ;) It also acts as a local SAMBA server, providing a way to share files, and provides printer services.

The firewall is also made to resist those who try to break into it. Even if someone were to get in, the system is pretty locked down (secure level 4), and the boot kernel and root FS are on an internaly mounted eject-disabled CD-ROM drive. So the worst that could be done is web-page mangling, and/or launch pointing, both of which would be picked up rather quickly. With the press of a button, the drives can be formated, re-installed, and back to a working (hopefuly more secure) state in under 10 minutes.

The firewall has also been designed from the start to have minimal power usage. This means everything from spinning down drives to entering sleep mode. The motherboard has one of the more advanced APM systems for its age, and the gadgets have been kept to a minimum to allow its UPS to provide optimal up-time during power outages. Since it also works as the house alarm sysem, it needs to be on, especialy when the power is out, to record would-be burglers. Paranoid? Maybe, but sometimes thats a good thing, right?
And good luck finding it if you break into the house. It's hidden. :)