Firewall Part 1: Hardware

The offered by ISPs devices for connecting to the Internet are a great and inexpensive solution to a computer, more or to also connect an entire household to the Internet. It can be found equipment from renowned manufacturers: AVM, Speedport (Funkwerk, AVM), rare Zyxel or D-Link. They are assigned to all of the device class router. Depending on the manufacturer and ISP provides the firmware ausfgespielte different settings which are to a large extent to designate from spartan to. For everyday needs, these are usually enough. It can ports routed to internal clients, dyndns provider can be managed and sometimes deposited a small blacklist of blocked sites.

In enterprise firewalls are an integral part. They protect the internal network from unauthorized access from outside, can scan for viruses and also prevent a ping to the WAN interface. Firewalls can be a much finer control of Interetverkehrs to as a router. While a router for internally initiated connection a port opens and allows the connection, a firewall can accurately filter which internal connections are allowed by external. Firewalls in Unternemen have additional security features such as IDS / IPS, Proxy, Blacklist etc. Mostly costs.

Hardware

For private home use, it must of course be no firewall appliance such as is used in business. However, the hardware should bring sufficient power to proxy, virus scanner, To operate IPS / IDS and an OpenVPN server. For this, of course, lends itself to Discarded PC Hardware. Who has space and can hide the device in a corner is flirting with this solution because it provides a quick and cheap solution. Apart from the power consumption. Who wants but rather have the form factor of current router must look around for alternatives. Small boards with multiple network interfaces and a nice housing are rare. One of the few manufacturers Alix. The Alix 1D APU is available with 2GB and 4GB ram. The other specifications of the boards:

    • Processor: 1,0 GHz AMD Embedded G-Series T40E APU (Dual-Core, 64 Bit Support, 32 + 32 KByte L1 Cache, 2 x 512 KByte L2 Cache, SSE1,2,3, SSSE3 ISA, SSE4A, MMX, AMD-V) 2 GByte DDR3-1066 DRAM memory (not extendable)
    • 1 x SD-Connector (bootable)
    • 1 x SATA 6 GBit/s Connector
    • 1 x mSATA 6 GBit/s Connector
    • 3 x 10/100/1000 MBit/s (Realtek RTL8111E) NOTHING
    • 1 x 9-pol. serial (console connector)
    • 2 x USB 2.0
    • 2 x Mini PCIe Socket
    • 1 x SIM Socket
    • RTC Battery, GPIO-Pins, LPC-Pins, COM2-Port (3,3V RxD/TxD), Onboard USB Plug
    • 3 LEDs and 1 Pushbutton-Switch (programmable)
    • CoreBoot Open Source System BIOS, iPXE & USB Boot
    • Energy Connector: +12V DC
    • Energy Consumption: 6-12W
    • Form: 152,4 x 152,4 mm

should To replace a full-fledged router, the device can be equipped with additional components:

    • Atheros Wireless Card – Accesspoint
    • Wlan Antenna
    • Wlan Antenna Connector
    • Mobile SSD – Cache Management Proxy

The following things are to take the equipment still needed:

    • COM Port an Laptop oder PC -> Alternativ einen USB to RS-232 Adapter
    • Serial null modem cable

Alix APU Chassis

Some notes on the chosen set-up:

  1. To operate the firewall successfully on a connection using a modem or upstream router is needed. The Alix APU does not have a built-in modem. ISPs such as Telekom distribute almost exclusively only Speedport devices and are not pure Modems. In the environment described here is a Sphairon Speedlink 1113 Adsl / 2 modem uses.
  2. Next the Alix board does not allow a phone to connect. Here, the configuration of an upstream router would be preferable or switch to SIP telephony.

ME

Leave a Reply

Your email address will not be published. Required fields are marked *

Consent to the Privacy Policy

This site uses Akismet to reduce spam. Learn how your comment data is processed.