A Badass Firewall From A Junk PC
Monday, February 11th, 2008 running time 14:31
If it's got a 386 processor and 32MB of RAM, and you can find a pair of Ethernet cards, you can turn that Junk PC into a serious Firewall to protect your network.
Ah, the wonder that is IPCop... a free Open Source firewall you can run on 'junk PC' hardware.
We walk you thru the installation on this episode of Systm: It'll keep your network seriously safe.
But don't take our word for it: InfoWorld gave it a Best of Open Source Security Award for aka a 'Bossie' for Best Firewall and PCPro gave it Five Stars in their review.
It's essentially a stripped down and focused Linux distribution that does nothing but stateful packet inspection, Snort intrusion prevention, IPSec VPN, and plug holes bad gals on the Internet might use to get on your network).
The main trick in setting up IPCop, after, of course, you've found an old Intel/AMD/Cyrix/Via/whichever machine that still runs, is securing a couple of compatible Ethernet cards... check cards against the IPCop Hardware Compatibility List before you buy 'em!
You can download it here... we prefer the ISO version you can burn to a bootable CD-ROM, it's called "ipcop-1.4.18-install-cd.i386.iso"
Check out the documentation before you start, and definately take soem time to check out the laundry list of IPCop Add Ons you can use to customize your IPCop installation with various filters, servers and (sweet!) OpenVPN.
Check it out!
Highlights
computer networking
(
6:15, 6:15
)
hard drive
(
1:03, 3:37, 3:50, 3:57, 4:31, 4:37, 4:41, 1:03, 3:37, 3:50, 3:57, 4:31, 4:37, 4:41
)
Green Zone
(
2:50, 2:50
)
open source
(
14:00, 14:00
)
computer networking
(
6:15, 6:15
)
hard drive
(
1:03, 3:37, 3:50, 3:57, 4:31, 4:37, 4:41, 1:03, 3:37, 3:50, 3:57, 4:31, 4:37, 4:41
)
Green Zone
(
2:50, 2:50
)
open source
(
14:00, 14:00
)
Automatically Generated Transcript(may not be 100% accurate) ( more )
" A -- Norton -- this system thing greetings from the lab of hoping coffee somewhere here on the outskirts of San Francisco. Nor protect your home network or business networking and firewall. Firewalls are expensive not really what we're actually gonna do today is turn -- jangled PC hardware and some free software off the Internet. Into a very robust firewalls. And has always want to thank our sponsors this week it's go to -- dot com and Netflix dot com. And right now we're gonna teach you how to build a firewall using IP cop on the Simpson in the system. All right it is long -- machine wasn't dead do a foggy salt entrance station they killed the motherboard it would be perfect candidate. For an IP copies firewall watched its low power it's got memory and it's got hard drive inside of it that's pretty much everything you need. To run IP top all the you're gonna need a monitor. And a CD-ROM drive or dvd rom drive the read CD roms to install at least in the preferred way we do it. Now it's -- about a firewall is it something it's basically -- keeper between a network at home more network at work in the big bad stuff happening out on the Internet. Now if you look at the network diagram easily draw on the Internet as a cloud which is a really great the image because the area is basically made up of everything connects based on an IP address which means their servers are switches and about a gazillion other things. There's also a lot of nasty people that want to -- criminally obnoxious things or maybe not criminally obnoxious maybe just obnoxious depending on more than living and they may want to do empty your machines. Part of -- robust security set up your home or at your office is having a firewall in place that you may be taking yourself I -- firewall I have a cable modem that's like a firewall right well maybe accident I think what you -- figuring if you have a cable modem and you connect -- the cable modem it's exactly like being on the same -- with everybody else in your neighborhood. Fact it's not practically it is being on the same note and everybody else neighborhood. What does that mean. We have fourteen year old this'll really cool stuff with computers and downloads lot of stuff may be actually be doing something really Narnia in your commuters could you're basically exposed on the same network. That you put a firewall between you and that network you're actually protecting yourself because a firewall does an inspection of every packet that comes through with school but IP company doesn't sophisticated analysis like staple packet inspection. Plus a whole much other stuff we'll talk about a minute right down -- which need to know is having a firewall in place even the most basic firewall on home routers isn't very good idea. And having the firewall like IP copy this and sophisticated analysis is a great idea. I think -- the budget that works in zone just two primaries on the red zone and the greens out. The Green Zone is everything behind the firewall offer network appliance is all your machines the red zone is basically that little tiny heavily monitored connection to the Internet. And that's Italy is to my favorite friend on the IP -- website. The fabulous. Hardware compatibility list the hard -- about -- compatible network devices that are primarily ethernet -- And mode this. And DSL highest the end cards before you install like peacock basically want to assemble the entire system together there's a couple things you wouldn't need temporarily. Actually three things your monitor. Your keyboard. And CD-ROM drive you can't installed through a floppy disk or maybe USB guess we refuse to see -- round out 'cause it's so simple to burn myself. The permanent elements of your machine. Are you mix your network interface cards your motherboard your memory in your hard drive although in our case we -- CF adapter and -- CF card that we're gonna use. Now the only downside and he's like a two gigabyte CF card instead of a 300 you know megabits or 300 gigabyte. Probably overkill there. Hard drive is that you basically can only store the small part of the through log files you can store since you're really enjoy log -- now -- you limping hard drive. Soon you check the hardware compatibility list you've got your hardware together yet you -- she -- You're kind of -- IP -- to install right IP copilot SourceForge dot net go to the download link and look at that it's like. Eighteen zillion different versions here. Generally speaking we download the -- so version of the I 386 of the latest version of that. Why has agreed to bootable installation CD basically you -- favorite CD burning software to open up the -- so creative portable disk. So you're gonna have to make your CD-ROM bootable inside the bios at least for the very first configuration. And while you're in their -- that your hard drive is recognized by the -- what you do from the CD you should see window like -- see the big red stuff in the middle that means anything on the hard drive is gonna be white. Back up anything you want off the hard drive before you install I -- out it's got a level everything. Story about this Athlon -- hardware premise stuff hit and are. And the fabulously exciting Linux boot process has -- Language of choice IP top installation and this is greats. Okay. Basically as -- we're gonna install it you do network installation we're gonna CD-ROM installation. Announcements are proving your system looking for hardware. Great time to go make a sandwiched. Maybe start a movie. We like to pause for a brief commercial break to thank our sponsors first up go to -- dot com. They do and make an impact on mine do it would go to any dot com dot com names as low as one dollar and 99 cents plus world class hosting fast and easy website builders and much more. Now you want to discount and of the code since one that's SYS one when you check out you can save an additional ten dollars off any order of forty dollars or more. Almost forgot if you like -- more than one device to your firewall -- need a hub or switch between it and the rest of your network obviously all the individual lines and network and that's what we have right down here. Another amazing 25 dollar computer flea market purchase. -- The restore many you're gonna see here it's basically only if you're rebuilding the -- is an older IP cop installation your not so we're gonna. Hit the space -- to skipped. -- where -- can get really really confused computer networking setting up those on the green is the once inside your house the red is the one that tax the Internet. If you're using like nine of the same. Internet card nick for the network interface card not a problem in our case want to make sure the dignity ethernet cards -- green network. And he. 10100 card is connecting to your cable modem. So it's gonna search. Or probe as it calls it digital point one explored great this is the actual and we went through basically we used IP cop who pulled one Nikki and booted IP company identified the card make sure we knew which was which and greatest moment while we're gonna hit and her we're -- and I. It was a great time to write this information down. Okay -- hear that that was the sound of the CD-ROM being spit out that's because once the initial file installation is done. You do not need the installation CD-ROM anymore and in fact you want to pull out otherwise your machine will keep booting into that. So. There's really copy -- a little while the other thing it's kind of important here is you're going to law again. TU IP top. After it restarts so you need a second machine connected to your hub connecting your IP comp box -- you -- the configuration over the HTTP your your web based connection. For that though community some final configuration. Time zone so you log information is correctly identified. We're gonna call this IP. Manage your local network name. If you don't -- highest end cards down in the civilized the end. There's an important network configuration type."
" Is is on you have remember -- green is here interior network reddish or connection to the big bad Internet. Oranges if you want to firewall or DMZ some servers when exposed to the Internet to blue is. And optional connection to you you wireless access systems he basically. DMZ off any Wi-Fi connections you have a review of basic green plus red. Which gives us our -- is motorized Janet green plus red -- going to be checked into our cable modem. We hit OK. And it's gonna search again. -- go to the drivers in part assignments. -- unknown that's bad because we have actually have a tendency anything and remember you have to connect to configure all of your hardware during the initial installation if you don't -- and then later. If you can I've figured out. There -- others -- second card we've probed forward its mandates. Address settings. Creating going to be DH CP it's good place to starts. Okay. Read reviews the ACP. -- the space bar. And renewed have that song -- Okay and don't. So this is -- TCP on the inside of a network. Music very large collection of -- We'll find. America. And split this can be a little frustrating because when you're entering in passwords I peacock is so secure. It didn't tell you how many characters are entering so. You have to do this for three sets of passwords. And every time passwords don't match what keeps you backing and all right now we're gonna re boots. And."
" We are now going to log into this machine after -- from our second machine. Okay a brief moment to thank our sponsors the folks that keep bringing the show to you by keeping us employed that's a good thing. As we get to the Tekzilla brought you my Netflix if you like high deputy now get both the Blu-ray and HD dvd movies through Netflix their fabulous home delivery service. We need a free trial out of them by signing up through a site they set up just for us at www. Netflix dot com slash system that's SYS TM. All right so. Look at this I -- up log in and monitor here which we will soon removed never to be attached again along the keyboard to do not -- blogging here you're gonna go to your system. That's connected to the hub that's connected to -- network card of the screen interface card the green mixed on your IP top box. Can reduce cure all the NET TVS Colin slash slash IP top called 445 were hit tanner and magical things are going to happen -- We're doing it right here is the IP top administration. The first time we do this you are gonna have to -- connect button if you don't hit that connect button. Com you may find out she had no Internet connection you're tired frustrated angry. If you your DTP committed changes regularly like hearing your cable modem company your DSL company. Plays around with your gates' appearance at random IP address they give you hit the refresh button that's take care that so. -- area here's the homepage to see how long are up time is I think it's -- whopping four minutes I've seen these up and running for months and months. Your network you basically not going to be using what you're doing a dial up modem. Status your system status lets you know higher hardware is doing and what's attached to your system. Modules that are currently in place teaming up what's attaches to what hardware sort of place. -- system sense if you're ninety and what services are running on the system. And I your memory usage and stuff like that like you said he told me lot of memory reasoning while being. I've read that right 32 inch thirty megabytes here. Disk usage. Began the entire space left on that yet -- Four point two gigabytes for log file storage. Up time which is now to a whopping five minutes and we do this. Network status which you know. What's connected to ethernet zero or three network -- network. And things are looking really good we've got a TTP configuration -- thank -- for cable modem. -- intrusion detection the cool guy looking for nasty packets on there is not set up to do that you're gonna actually have to doing TV services and intrusion detection. And you're gonna have to register actually. To get access to the rules -- need for that."
" We're gonna go often do that meantime want to remind you this is really fun really easy great way to recycle hardware it's a fun we learn about firewalls and network configuration in that sense and take a look at what is actually happening. How they're in the big bad Internet trying to knock on your door. Really great community around nine. Ethical rules trivia. Intrusion detection system and -- An interesting way to learn about how network security here it's agree with circling around with networking to get sort of more intensity might have a typical. Home routers system -- some really cool suffering actually lower than the RT 54 G if you have a right model that can actually among alternative when -- operating system. Not gonna get into that today we are gonna definitely tell you though. You know I -- at SourceForge dot net check out all the documentation it's available search ran on the web this is a hugely popular very robust firewall to extremely popular not just in the open source community about. With people and actually protect networks for living. Check it out go to the boards and learn the lots and have fun I'm Patrick Norton that's in the surface system. And we'll see you next week."
" A -- Norton -- this system thing greetings from the lab of hoping coffee somewhere here on the outskirts of San Francisco. Nor protect your home network or business networking and firewall. Firewalls are expensive not really what we're actually gonna do today is turn -- jangled PC hardware and some free software off the Internet. Into a very robust firewalls. And has always want to thank our sponsors this week it's go to -- dot com and Netflix dot com. And right now we're gonna teach you how to build a firewall using IP cop on the Simpson in the system. All right it is long -- machine wasn't dead do a foggy salt entrance station they killed the motherboard it would be perfect candidate. For an IP copies firewall watched its low power it's got memory and it's got hard drive inside of it that's pretty much everything you need. To run IP top all the you're gonna need a monitor. And a CD-ROM drive or dvd rom drive the read CD roms to install at least in the preferred way we do it. Now it's -- about a firewall is it something it's basically -- keeper between a network at home more network at work in the big bad stuff happening out on the Internet. Now if you look at the network diagram easily draw on the Internet as a cloud which is a really great the image because the area is basically made up of everything connects based on an IP address which means their servers are switches and about a gazillion other things. There's also a lot of nasty people that want to -- criminally obnoxious things or maybe not criminally obnoxious maybe just obnoxious depending on more than living and they may want to do empty your machines. Part of -- robust security set up your home or at your office is having a firewall in place that you may be taking yourself I -- firewall I have a cable modem that's like a firewall right well maybe accident I think what you -- figuring if you have a cable modem and you connect -- the cable modem it's exactly like being on the same -- with everybody else in your neighborhood. Fact it's not practically it is being on the same note and everybody else neighborhood. What does that mean. We have fourteen year old this'll really cool stuff with computers and downloads lot of stuff may be actually be doing something really Narnia in your commuters could you're basically exposed on the same network. That you put a firewall between you and that network you're actually protecting yourself because a firewall does an inspection of every packet that comes through with school but IP company doesn't sophisticated analysis like staple packet inspection. Plus a whole much other stuff we'll talk about a minute right down -- which need to know is having a firewall in place even the most basic firewall on home routers isn't very good idea. And having the firewall like IP copy this and sophisticated analysis is a great idea. I think -- the budget that works in zone just two primaries on the red zone and the greens out. The Green Zone is everything behind the firewall offer network appliance is all your machines the red zone is basically that little tiny heavily monitored connection to the Internet. And that's Italy is to my favorite friend on the IP -- website. The fabulous. Hardware compatibility list the hard -- about -- compatible network devices that are primarily ethernet -- And mode this. And DSL highest the end cards before you install like peacock basically want to assemble the entire system together there's a couple things you wouldn't need temporarily. Actually three things your monitor. Your keyboard. And CD-ROM drive you can't installed through a floppy disk or maybe USB guess we refuse to see -- round out 'cause it's so simple to burn myself. The permanent elements of your machine. Are you mix your network interface cards your motherboard your memory in your hard drive although in our case we -- CF adapter and -- CF card that we're gonna use. Now the only downside and he's like a two gigabyte CF card instead of a 300 you know megabits or 300 gigabyte. Probably overkill there. Hard drive is that you basically can only store the small part of the through log files you can store since you're really enjoy log -- now -- you limping hard drive. Soon you check the hardware compatibility list you've got your hardware together yet you -- she -- You're kind of -- IP -- to install right IP copilot SourceForge dot net go to the download link and look at that it's like. Eighteen zillion different versions here. Generally speaking we download the -- so version of the I 386 of the latest version of that. Why has agreed to bootable installation CD basically you -- favorite CD burning software to open up the -- so creative portable disk. So you're gonna have to make your CD-ROM bootable inside the bios at least for the very first configuration. And while you're in their -- that your hard drive is recognized by the -- what you do from the CD you should see window like -- see the big red stuff in the middle that means anything on the hard drive is gonna be white. Back up anything you want off the hard drive before you install I -- out it's got a level everything. Story about this Athlon -- hardware premise stuff hit and are. And the fabulously exciting Linux boot process has -- Language of choice IP top installation and this is greats. Okay. Basically as -- we're gonna install it you do network installation we're gonna CD-ROM installation. Announcements are proving your system looking for hardware. Great time to go make a sandwiched. Maybe start a movie. We like to pause for a brief commercial break to thank our sponsors first up go to -- dot com. They do and make an impact on mine do it would go to any dot com dot com names as low as one dollar and 99 cents plus world class hosting fast and easy website builders and much more. Now you want to discount and of the code since one that's SYS one when you check out you can save an additional ten dollars off any order of forty dollars or more. Almost forgot if you like -- more than one device to your firewall -- need a hub or switch between it and the rest of your network obviously all the individual lines and network and that's what we have right down here. Another amazing 25 dollar computer flea market purchase. -- The restore many you're gonna see here it's basically only if you're rebuilding the -- is an older IP cop installation your not so we're gonna. Hit the space -- to skipped. -- where -- can get really really confused computer networking setting up those on the green is the once inside your house the red is the one that tax the Internet. If you're using like nine of the same. Internet card nick for the network interface card not a problem in our case want to make sure the dignity ethernet cards -- green network. And he. 10100 card is connecting to your cable modem. So it's gonna search. Or probe as it calls it digital point one explored great this is the actual and we went through basically we used IP cop who pulled one Nikki and booted IP company identified the card make sure we knew which was which and greatest moment while we're gonna hit and her we're -- and I. It was a great time to write this information down. Okay -- hear that that was the sound of the CD-ROM being spit out that's because once the initial file installation is done. You do not need the installation CD-ROM anymore and in fact you want to pull out otherwise your machine will keep booting into that. So. There's really copy -- a little while the other thing it's kind of important here is you're going to law again. TU IP top. After it restarts so you need a second machine connected to your hub connecting your IP comp box -- you -- the configuration over the HTTP your your web based connection. For that though community some final configuration. Time zone so you log information is correctly identified. We're gonna call this IP. Manage your local network name. If you don't -- highest end cards down in the civilized the end. There's an important network configuration type."
" Is is on you have remember -- green is here interior network reddish or connection to the big bad Internet. Oranges if you want to firewall or DMZ some servers when exposed to the Internet to blue is. And optional connection to you you wireless access systems he basically. DMZ off any Wi-Fi connections you have a review of basic green plus red. Which gives us our -- is motorized Janet green plus red -- going to be checked into our cable modem. We hit OK. And it's gonna search again. -- go to the drivers in part assignments. -- unknown that's bad because we have actually have a tendency anything and remember you have to connect to configure all of your hardware during the initial installation if you don't -- and then later. If you can I've figured out. There -- others -- second card we've probed forward its mandates. Address settings. Creating going to be DH CP it's good place to starts. Okay. Read reviews the ACP. -- the space bar. And renewed have that song -- Okay and don't. So this is -- TCP on the inside of a network. Music very large collection of -- We'll find. America. And split this can be a little frustrating because when you're entering in passwords I peacock is so secure. It didn't tell you how many characters are entering so. You have to do this for three sets of passwords. And every time passwords don't match what keeps you backing and all right now we're gonna re boots. And."
" We are now going to log into this machine after -- from our second machine. Okay a brief moment to thank our sponsors the folks that keep bringing the show to you by keeping us employed that's a good thing. As we get to the Tekzilla brought you my Netflix if you like high deputy now get both the Blu-ray and HD dvd movies through Netflix their fabulous home delivery service. We need a free trial out of them by signing up through a site they set up just for us at www. Netflix dot com slash system that's SYS TM. All right so. Look at this I -- up log in and monitor here which we will soon removed never to be attached again along the keyboard to do not -- blogging here you're gonna go to your system. That's connected to the hub that's connected to -- network card of the screen interface card the green mixed on your IP top box. Can reduce cure all the NET TVS Colin slash slash IP top called 445 were hit tanner and magical things are going to happen -- We're doing it right here is the IP top administration. The first time we do this you are gonna have to -- connect button if you don't hit that connect button. Com you may find out she had no Internet connection you're tired frustrated angry. If you your DTP committed changes regularly like hearing your cable modem company your DSL company. Plays around with your gates' appearance at random IP address they give you hit the refresh button that's take care that so. -- area here's the homepage to see how long are up time is I think it's -- whopping four minutes I've seen these up and running for months and months. Your network you basically not going to be using what you're doing a dial up modem. Status your system status lets you know higher hardware is doing and what's attached to your system. Modules that are currently in place teaming up what's attaches to what hardware sort of place. -- system sense if you're ninety and what services are running on the system. And I your memory usage and stuff like that like you said he told me lot of memory reasoning while being. I've read that right 32 inch thirty megabytes here. Disk usage. Began the entire space left on that yet -- Four point two gigabytes for log file storage. Up time which is now to a whopping five minutes and we do this. Network status which you know. What's connected to ethernet zero or three network -- network. And things are looking really good we've got a TTP configuration -- thank -- for cable modem. -- intrusion detection the cool guy looking for nasty packets on there is not set up to do that you're gonna actually have to doing TV services and intrusion detection. And you're gonna have to register actually. To get access to the rules -- need for that."
" We're gonna go often do that meantime want to remind you this is really fun really easy great way to recycle hardware it's a fun we learn about firewalls and network configuration in that sense and take a look at what is actually happening. How they're in the big bad Internet trying to knock on your door. Really great community around nine. Ethical rules trivia. Intrusion detection system and -- An interesting way to learn about how network security here it's agree with circling around with networking to get sort of more intensity might have a typical. Home routers system -- some really cool suffering actually lower than the RT 54 G if you have a right model that can actually among alternative when -- operating system. Not gonna get into that today we are gonna definitely tell you though. You know I -- at SourceForge dot net check out all the documentation it's available search ran on the web this is a hugely popular very robust firewall to extremely popular not just in the open source community about. With people and actually protect networks for living. Check it out go to the boards and learn the lots and have fun I'm Patrick Norton that's in the surface system. And we'll see you next week."










