What's new

Firewall Script?

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

JT Strickland

Very Senior Member
Anybody know of a good firewall script they would recommend?
 
Thanks, but I was looking for something, ... different. If there is such a thing.
It's been a good ol' friend, and I would hate to part with it, but I may not have any choice in the matter.
 
The only thing I would leave Skynet for is a dedicated device with pfSense or something.
 
The only thing I would leave Skynet for is a dedicated device with pfSense or something.
I am worried about Skynet leaving me. How long will it continue to work with newer firmware without updates? Seems there are already problems.
 
It may come to that. I like the added security of actively trying to block the enemy from doing me and my family harm.
Maybe it is superficial, but it makes me feel warm and fuzzy.
 
It seems Pfsense and Opnsense may require a dedicated device to run on. While that could be the best choice, it doesn't fit in my little network model very well.
 
Please excuse my ignorance. How does suricata fit into this kind of thing? I am running skynet too but aside from that I am concerned generally about my network and its vulnerabilities, and trying to keep in mind that "security is a process ..." and all that.
 
Please excuse my ignorance. How does suricata fit into this kind of thing? I am running skynet too but aside from that I am concerned generally about my network and its vulnerabilities, and trying to keep in mind that "security is a process ..." and all that.
From what little I have read, which is not much, Suricata is a similar script that needs investigating on my part.
On the other hand, from a recent post, it looks like Skynet was updated yesterday to fix an issue, so it's not in the boneyard yet.
 
For me, it's too soon to leave skynet, maybe not for a long time. I am wondering if suricata has capabilities that skynet does not, and if running both makes any sense or might just add conflicts.
 
From what I can tell, Adamm is still maintaining Skynet; just not as actively as he once did. Further, changes to the script would only be required if something in the firewall breaks it, as you already mentioned. As long as that doesn't happen, Skynet should continue to function just fine even if Adamm never raises another finger to tweak the code.

Suricata is quite powerful; I think borderline too powerful for the hardware in our routers; I'm looking at an HP T620+ (thin client) to run that. But really I'd like to have Skynet outside the pfSense box... but then that becomes
INTERNET <=> Asus w/ Skynet <=> pfSense box <=> Asus w/ other scripts <=> LAN/WLAN

Seems complicated. :p
 
Please excuse my ignorance. How does suricata fit into this kind of thing? I am running skynet too but aside from that I am concerned generally about my network and its vulnerabilities, and trying to keep in mind that "security is a process ..." and all that.
Suricata is an IDS/IPS (similar to AiProtection). Skynet is a firewall.
 
For me, it's too soon to leave skynet, maybe not for a long time. I am wondering if suricata has capabilities that skynet does not, and if running both makes any sense or might just add conflicts.
Me too, I was trying to prepare for if it left me. It was good to see a small update yesterday. It would be good to hear from Adamm once again too.
 
Well yes. And most things are too complicated for me already, I don't need to add more. But I _really_ like the idea of intrusion detection (and egress monitoring from my vague understanding of that). Generally, I feel better having some idea of what's going on.
 
Suricata is an IDS/IPS (similar to AiProtection). Skynet is a firewall.
Thanks. I appreciate. If I remember correctly, there are instructions for adding Suricata to the router. I may try it, sometime. :)
 
there is also Snort3, another ips similar to Suricata. The link is about all I know:
 
Yes, Snort is an older piece of software; Suricata has replaced it for most people IIRC. My main concern is that I don't think our routers have enough power to run those... possibly the 88. Or... you'll see your throughput plummet if you're trying to inspect all the packets. That's why I'd love to have Skynet outside Suricata - blocks a bunch of stuff that then Suricata doesn't need to worry about scanning.

Still - to some extent it depends on your connection speed. If you have gigabit, no way is your router going to keep up... heck even people with a dedicated HP T620+ can't keep up with gigabit. If you have a much slower connection then it's more plausible.
 

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top