2010 09-22 infra rn security meeting - palestra firewalls opensource

79
Eduardo Coelho http://coelho.ithub.com.br

Upload: eduardo-coelho

Post on 30-May-2015

347 views

Category:

Documents


1 download

TRANSCRIPT

Page 1: 2010 09-22 infra rn security meeting - palestra firewalls opensource

Eduardo Coelho

http://coelho.ithub.com.br

Page 2: 2010 09-22 infra rn security meeting - palestra firewalls opensource

Eduardo Coelho

Page 3: 2010 09-22 infra rn security meeting - palestra firewalls opensource

Porque isso muda tudo BSD license x GPL

Page 4: 2010 09-22 infra rn security meeting - palestra firewalls opensource

Firewall Opensource

Page 5: 2010 09-22 infra rn security meeting - palestra firewalls opensource

Linux

FreeBSD

OpenBSD

Page 6: 2010 09-22 infra rn security meeting - palestra firewalls opensource

Netfilter/Iptables (+IProute2+HTB/CBQ)

IPFW

PF

Page 7: 2010 09-22 infra rn security meeting - palestra firewalls opensource
Page 8: 2010 09-22 infra rn security meeting - palestra firewalls opensource
Page 9: 2010 09-22 infra rn security meeting - palestra firewalls opensource
Page 10: 2010 09-22 infra rn security meeting - palestra firewalls opensource

Absurdamente rápidos

Processam tráfego de rede

By default já rodam no kernel

Features incluem:

Statefull inspection

QoS/Priorization

Static Routing

Dynamic Routing*

Page 11: 2010 09-22 infra rn security meeting - palestra firewalls opensource

Fwbuilder

Shorewall

Page 12: 2010 09-22 infra rn security meeting - palestra firewalls opensource
Page 13: 2010 09-22 infra rn security meeting - palestra firewalls opensource

Instalação no Debian:

#aptitude install shorewall

Quick Start Guide:

http://www.shorewall.net/

shorewall_quickstart_guide.htm

Page 14: 2010 09-22 infra rn security meeting - palestra firewalls opensource
Page 15: 2010 09-22 infra rn security meeting - palestra firewalls opensource

Instalação no Debian:

#aptitude install fwbuilder

OBS: requer X instalado

Instalação Windows (comercial)

http://www.fwbuilder.com

17 MB download

Next->Next->Finish

Quick Start Guide:

http://www.fwbuilder.org/

4.0/docs/users_guide/

gettingstarted.html

Page 16: 2010 09-22 infra rn security meeting - palestra firewalls opensource
Page 17: 2010 09-22 infra rn security meeting - palestra firewalls opensource
Page 18: 2010 09-22 infra rn security meeting - palestra firewalls opensource

Licença dupla GPL+Comercial

Versão Windows empacotada somente na comercial

Suporte diversos firewalls, incluindo Netfilter, IPFW, PF

GUI

Page 19: 2010 09-22 infra rn security meeting - palestra firewalls opensource

Squid

Dansguardian

Page 20: 2010 09-22 infra rn security meeting - palestra firewalls opensource

Instalação no Debian:

#aptitude install squid

É um Proxy HTTP (Acelerador)

Possibilidade de Gerar Relatórios (SARG)

Config Examples:

http://wiki.squid-cache.org/

ConfigExamples/

Page 21: 2010 09-22 infra rn security meeting - palestra firewalls opensource
Page 22: 2010 09-22 infra rn security meeting - palestra firewalls opensource

Faz uso intenso de RAM, HD e CPU e na maioria dos casos requerer um hardware de PC/Server

Possui uma grande comunidade de usuários

Curva de aprendizado lenta

Permite controle de banda simples via delay_pools (controle de taxa de transferência para download)

Pode ser usado como Reverse Proxy (Acelerador de Aplicação)

Page 23: 2010 09-22 infra rn security meeting - palestra firewalls opensource

Instalação no Debian:

#aptitude install dansguardian

Processa 100% do conteúdo via String Match

Ubuntu Config Example:

http://www.pilpi.net/journal/

2006/03/setting-up-

dansguardian-on-a-single-home-

pc-running-ubuntu/

Page 24: 2010 09-22 infra rn security meeting - palestra firewalls opensource
Page 25: 2010 09-22 infra rn security meeting - palestra firewalls opensource

Não faz cache

É usado normalmente em conjunto com o squid

Possui uma grande comunidade de usuários

É usado em milhares de escolas, bibliotecas e faculdades para filtragem de conteúdo web

Page 26: 2010 09-22 infra rn security meeting - palestra firewalls opensource

Vyatta

Pfsense

Untangle

Monowall

Smoothwall

Zentyal

IPCop

Endian

ClearOS

Zeroshell

Proxmox

Page 27: 2010 09-22 infra rn security meeting - palestra firewalls opensource

Pfsense

Monowall

IPCop

Zeroshell

Page 28: 2010 09-22 infra rn security meeting - palestra firewalls opensource

Administração Web

Principais features

Statefull firewall

VPN

Traffic Shapping

DHCP

DNS

ISO = 18MB (!)

Page 29: 2010 09-22 infra rn security meeting - palestra firewalls opensource
Page 30: 2010 09-22 infra rn security meeting - palestra firewalls opensource
Page 31: 2010 09-22 infra rn security meeting - palestra firewalls opensource
Page 32: 2010 09-22 infra rn security meeting - palestra firewalls opensource

Administração Web

Principais features

Statefull firewall

VPN

Traffic Shapping

DHCP

DNS

ISO = 65MB

Page 33: 2010 09-22 infra rn security meeting - palestra firewalls opensource
Page 34: 2010 09-22 infra rn security meeting - palestra firewalls opensource
Page 35: 2010 09-22 infra rn security meeting - palestra firewalls opensource
Page 36: 2010 09-22 infra rn security meeting - palestra firewalls opensource

Administração Web Principais features Statefull firewall VPN Traffic Shapping DHCP DNS HTTP Proxy + Web antivirus LDAP SSL CA

VMware friendly ISO = 148MB

Page 37: 2010 09-22 infra rn security meeting - palestra firewalls opensource
Page 38: 2010 09-22 infra rn security meeting - palestra firewalls opensource
Page 39: 2010 09-22 infra rn security meeting - palestra firewalls opensource
Page 40: 2010 09-22 infra rn security meeting - palestra firewalls opensource

Administração Web

Principais features

Statefull firewall

VPN

Traffic Shapping

DHCP

DNS

ISO = 51MB

Page 41: 2010 09-22 infra rn security meeting - palestra firewalls opensource
Page 42: 2010 09-22 infra rn security meeting - palestra firewalls opensource
Page 43: 2010 09-22 infra rn security meeting - palestra firewalls opensource
Page 44: 2010 09-22 infra rn security meeting - palestra firewalls opensource

Vyatta

Untangle

Smoothwall

Zentyal

Endian

ClearOS

Proxmox

Page 45: 2010 09-22 infra rn security meeting - palestra firewalls opensource

Antigo E-BOX Principais features

Statefull firewall VPN Traffic Shapping DHCP DNS LDAP HTTP Proxy IDS SSL CA Zarafa (groupware) Samba Duplicity (backup) Jabber Asterisk Postfix

ISO = 470MB Install Only

Page 46: 2010 09-22 infra rn security meeting - palestra firewalls opensource
Page 47: 2010 09-22 infra rn security meeting - palestra firewalls opensource
Page 48: 2010 09-22 infra rn security meeting - palestra firewalls opensource
Page 49: 2010 09-22 infra rn security meeting - palestra firewalls opensource

Principais features

Statefull firewall

VPN

Traffic Shapping

DHCP

DNS

LDAP

HTTP Proxy

SSL CA

Postfix

ISO = 700MB

Page 50: 2010 09-22 infra rn security meeting - palestra firewalls opensource
Page 51: 2010 09-22 infra rn security meeting - palestra firewalls opensource
Page 52: 2010 09-22 infra rn security meeting - palestra firewalls opensource
Page 53: 2010 09-22 infra rn security meeting - palestra firewalls opensource

Mail Gateway

Principais features Statefull firewall VPN Traffic Shapping DHCP DNS LDAP SQL SSH

VMware friendly Suporte embutido para Kaspersky e

Avira

ISO = 345MB

Page 54: 2010 09-22 infra rn security meeting - palestra firewalls opensource
Page 55: 2010 09-22 infra rn security meeting - palestra firewalls opensource
Page 56: 2010 09-22 infra rn security meeting - palestra firewalls opensource
Page 57: 2010 09-22 infra rn security meeting - palestra firewalls opensource

CLI e WebGUI Opção para gateway de alto desempenho Posiciona-se como alternativa opensource a

Cisco e Juniper Principais features Statefull firewall VPN Traffic Shapping DHCP DNS LDAP QoS Bonding Load balancing Dynamic Routing

ISO = 164MB Boot CD

Page 58: 2010 09-22 infra rn security meeting - palestra firewalls opensource
Page 59: 2010 09-22 infra rn security meeting - palestra firewalls opensource
Page 60: 2010 09-22 infra rn security meeting - palestra firewalls opensource
Page 61: 2010 09-22 infra rn security meeting - palestra firewalls opensource

Estrutura de pacotes grátis e pagos facilita o licenciamento

Principais features Statefull firewall VPN Traffic Shapping DHCP DNS LDAP HTTP Proxy IDS SSL CA Samba

ISO = 456MB

Page 62: 2010 09-22 infra rn security meeting - palestra firewalls opensource
Page 63: 2010 09-22 infra rn security meeting - palestra firewalls opensource
Page 64: 2010 09-22 infra rn security meeting - palestra firewalls opensource
Page 65: 2010 09-22 infra rn security meeting - palestra firewalls opensource
Page 66: 2010 09-22 infra rn security meeting - palestra firewalls opensource

Principais features Statefull firewall VPN Traffic Shapping DHCP DNS LDAP HTTP Proxy IDS SSL CA Samba Asterisk Postfix

ISO = 78MB Install Only (No Live)

Page 67: 2010 09-22 infra rn security meeting - palestra firewalls opensource
Page 68: 2010 09-22 infra rn security meeting - palestra firewalls opensource
Page 69: 2010 09-22 infra rn security meeting - palestra firewalls opensource
Page 70: 2010 09-22 infra rn security meeting - palestra firewalls opensource

Principais features Statefull firewall VPN Traffic Shapping DHCP DNS LDAP HTTP Proxy IDS Samba Postfix

High availability NTLM SSO Hotspot

Hardware e Software Appliance

ISO = 130MB

Page 71: 2010 09-22 infra rn security meeting - palestra firewalls opensource
Page 72: 2010 09-22 infra rn security meeting - palestra firewalls opensource
Page 73: 2010 09-22 infra rn security meeting - palestra firewalls opensource
Page 74: 2010 09-22 infra rn security meeting - palestra firewalls opensource

OSSEC

Snort

SELinux

AppArmor

Tripwire

Fakeroot

Virtualização

Page 75: 2010 09-22 infra rn security meeting - palestra firewalls opensource

http://coelho.ithub.com.br

Page 76: 2010 09-22 infra rn security meeting - palestra firewalls opensource
Page 77: 2010 09-22 infra rn security meeting - palestra firewalls opensource
Page 78: 2010 09-22 infra rn security meeting - palestra firewalls opensource
Page 79: 2010 09-22 infra rn security meeting - palestra firewalls opensource