Print

Print


I'm collecting opinions regarding hardware to use for a firewall. If you
are interested in weighing in on this subject, I'm interested to hear
your ideas.

The hypothetical firewall is a purpose built OpenBSD box running OpenBSD
Packet Filter (pf), on a box that bridges the outside world to a
protected network of approximately 1000 nodes. The box needs to have a
network interface for administrative access via ssh, and two
high-throughput network interfaces to provide the "bridge" from the
protected network to the internet. 

Given this general scenario, what sort of box might you purchase and/or
assemble for this purpose? What elements would you consider critical?
(architecture, interfaces, harddrive or alternative, CPU, etc..)


   Thanks,
                Eric Weston, Libraries