> > This may work for a system where you are the sole admin but it does not
> > scale.  I work with a sysadmin who does as you do.  The print out of the
> > ruleset goes for pages.  Fortunately, the task of rewriting them has been
> > given to me.  Sanity will reign.
> As a point of curiosity for me, I have been interested in learning some
> of the aspects of the overhead associated with filtering (effectively)
> for security purposes. Haven't done any research yet, but if you know of
> some docs that address issues such as increased latency, propagation
> delays, effects on overall throughput, I would be interested. Or if you
> happen to gather these metrics during your rework, that would be useful.
> My particular interest ATM is deciding if I can use my DX2/66 as a
> gateway (not a lot of services to be exposed from behind the firewall)
> and firewall, or if I should used the AMD 5x86 100MHz, or separate the
> to functions. This is all new territory for me and feedback of the sort
> mentioned, HOWTOs and other resources will help me decide on the proper
> configuration. My current firewall is just "nothing gets in I didn't
> request, except smtp connects" on my RH 6.2 box. Will be insufficient
You'll be pleased to hear that some of the models Cisco has out for
routing/filtering T1 lines only have 33Mhz CPUs in them, so give it a
shot with the 66Mhz machine just filtering traffic and put the services
on the 100Mhz machine box.  If at all possible you want the firewall to
only be firewalling things, as this means there's going to be fewer
avenues for failure or entry into the bastion host.
