Endian firewall

from Wikipedia, the free encyclopedia
Endian firewall
EndianFirewallCommunityLogo.png
developer Endian
License (s) GPL ( Free Software )
Current  version Community Version 3.2.4 (September 26, 2017)
Kernel 4.1.17
ancestry GNU / Linux
↳ Red Hat Linux
↳ Fedora
↳ RHEL
↳ CentOS
↳ Smoothwall
↳ IPCop
↳ Endian firewall
Architecture (s) IA-32 , i686
Others Price: The community version is free, also available as a commercial product.
Installation language: English , German , Italian
Web interface language: 11 languages
www.endian.com

The Endian Firewall is a Linux distribution by the South Tyrolean company Endian . It specializes in router , firewall and gateway security functions. The product is optionally available as free software, as commercial software with guaranteed support services, or completely installed as hardware (appliance) including support services.

Brief description

The Endian Firewall is a turnkey Linux security distribution that sees itself as an independent, unified security management solution (Unified Threat Management). The Endian Firewall is based on a secure Linux operating system. The system is installed on a PC using a boot CD. After a few basic settings, the installation begins, partitioning the hard drive and transferring the files. The computer can then be operated without a monitor (headless). A keyboard and a monitor are no longer required, as the entire configuration of the server is carried out via a web interface (see figure "The web interface of the Endian Firewall") using another computer, which can be connected via the network - alternatively via the serial The system can be accessed via the interface.

The main task of the Endian Firewall is to act as a gateway, router and firewall as well as a proxy for web, email, FTP, SIP and DNS. Up to four different network zones are managed by Endian, see figure "Scheme of the network topology". A network card must be installed in the computer for each of these network zones. They are also configured via the web interface. With Endian, these are differentiated by color coding (see also figure "Scheme of the network topology"):

Network topology scheme
  • Red network : connection to the insecure internet
  • Green network : Secure intranet, the workplaces to be protected or intranet servers, e.g. B. file server connected.
  • Orange network : Partiallysecure demilitarized zone (DMZ) to operate your own servers that must be accessible via the Internet, e.g. B. Web or FTP server
  • Blue network : Partially secure WLAN, this is used to connect WLAN users. Thus, they are separated from the green network, which increases its security.

However, other, additional networks can be managed. The Endian Firewall also supports load balancing, i.e. H. you can add another connection to the Internet to the red network; Endian Firewall then distributes the network load over both interfaces.

License

Behind the Endian Firewall is the Italian Endian Spa from Eppan , South Tyrol and a community of volunteer developers and helpers. Endian's license model provides for a commercial version and a free version:

  • The commercial version can be purchased both as stand-alone software (Endian simply calls the product Endian UTM Software ) in order to install it on your own PCs, as well as in the form of ready-made out-of-the-box firewalls, in the sense of special hardware on which the software is pre-installed. There are currently four hardware variants with different capacities and for different network sizes: Mini , Mercury , Macro and Macro X2 .
  • The free version (the product is called Endian Firewall Community Version by Endian ) is, like the Endian UTM Software product, specialized software for installation on your own hardware. However, it is under the GPL , so it is free software and can be downloaded for free. The community version does not include support. Not all innovations in the commercial version are transferred to the community version (e.g. the hot-spot function for WLANs is reserved for the commercial version), and innovations sometimes appear in the community version with a time delay.

Range of functions

The current version includes the following main functions:

Gateway

  • Ethernet support
  • Load sharing
  • Traffic shaping
  • Multiple uplink support
  • Uplink failover

Firewall & Security

  • Firewall (both directions)
  • demilitarized zone
  • Intrusion Detection System / Intrusion Prevention System
  • Web, FTP, and email antivirus
  • Antispam
  • Content filter
  • HTTPS web interface
  • SSH access and forwarding
  • Automatic backup scheduler

Server services

  • Policy-based routing (interface, MAC address, protocol or port)
  • generic SNMP support
  • VLAN support (IEEE 802.1Q trunking)

User administration

  • Local
  • RADIUS
  • LDAP
  • Active Directory
  • NTLM single sign-on
  • User or group-wise HTTP proxy content filter rules

Logging & Monitoring

  • Visualized Live Log Viewer (AJAX based), see figure "The web interface of the Endian Firewall"
  • Log of activities and usage of network and hardware
  • Connection statistics
  • The syslogs can be forwarded to an external server
  • Home page with integrated DASH board
  • event-based notifications by email

Others

  • Software RAID support

History and comparison to the origin

The origin of the Endian firewall is the Linux firewall IPCop , which in turn is a spin-off from Smoothwall. Due to numerous further developments, according to Endian, only a fifth of the original IPcop code is currently used. For example, Endian now uses the RPM Package Manager , which simplifies maintenance and avoids the frequent, lengthy compilation times that are common with LFS-based distributions such as IPcop. Newer versions were initially based on Linux From Scratch and from version 2.2 on RHEL or CentOS . With the upcoming version 3.0, the Endian Firewall should be practically "Smoothwall-" and "IPcop-free".

The biggest difference to IPCop is that the Endian Firewall is no longer seen as a pure router / firewall combination, but as a comprehensive gateway security solution (Unified Threat Management). For this purpose, a virus scanner and a spam blocker have been permanently integrated into the distribution. This means that the traffic from HTTP , FTP , POP 3 and SMTP can be scanned in real time and filtered if necessary. As completely new features, several WAN connections (for simple load distribution , failover ) and a WLAN hot spot function have been integrated.

In addition, the menus have been refined by many points compared to IPCop, which enables a more precise configuration of the individual services, which, however, also increases the complexity.

In summary, one can say that the Endian Firewall is the more comprehensive solution compared to IPCop in terms of gateway security, but as a compromise a somewhat more extensive configuration and noticeably higher requirements for the hardware equipment have to be accepted (for the Use of the full functionality of 512 MB RAM and 1 GHz processor clock recommended, or 256 MB and 500 MHz specified as minimum equipment).

In terms of development and business model, Endian differs from its origins Smoothwall and IPCop as follows:

  • Smoothwall: Development of a commercial version by Smoothwall Ltd. as well as a free version by a community of volunteers. Innovations in the commercial version are only partially integrated into the free version, security updates are sometimes deliberately delayed. This company policy was the reason for part of the community to split off to IPCop
  • IPCop: Development exclusively by a community of volunteers, there is only one free version.
  • Endian Firewall: Friendly spin-off from IPCop with the aim of adding functions to the software in order to create an all-encompassing security gateway software. As with Smoothwall, there are functions in the commercial version that the free community version lacks.

Current development and criticism

Since the community versions 2.3 and 2.4, critical voices have been increasingly loud in the relevant user forums around Endian. Mainly three issues are criticized:

  1. Stability and freedom from errors: While release 2.2 was still considered stable and mature, many users found the long awaited version 2.3 a disaster in terms of freedom from errors. All services, e.g. For example, the VPN module did not work for many users, so that using this release as a productive system was out of the question and they had to downgrade to 2.2 again. Many users expected that 2.4 would fix these bugs, but in many cases this did not happen. Version 2.4 is often referred to as even more buggy than 2.3. Many users could not even install it due to errors in the installation routine, so that Endian was forced to quickly replace the version offered for download with one that was improved in this regard (recognizable by the filename extension "RESPIN").
  2. In connection with the poor quality of the last releases, the communication and transparency of the development process on the part of Endian Spa are increasingly being criticized. The company does offer a version known as the “community version” and on the homepage it appears that there is a community around the product - critical voices claim, however, that Endian does not have a real community in the sense of participating in the development , and no or only very sparse communication with the users of the community version would take place.
  3. Endian was developed exclusively by Endian Spa, the entire development process is non-transparent and takes place "behind closed doors". The users of the community version, referred to by Endian as community, are not even included in a beta test or informed about future development goals, which means that participation in the development is not possible. As a result, voices are repeatedly heard discussing a possible fork .

resonance

  • The Endian Firewall is part of the c't Debian Server Version 4 (released in August 2009) and was already in 2007.
  • In July 2005 the Endian Firewall was voted Project of the Week by OSDir.
  • The Linux Magazin 09/2008 tested Endian Firewall UTM Appliances 2.2 and certified the system with a test result in the upper midfield of comparable products.

Web links

Individual evidence

  1. http://distrowatch.com/?newsid=04686
  2. http://distrowatch.com/?newsid=05731
  3. Archive link ( Memento of the original from September 7, 2012 in the web archive archive.today ) Info: The archive link was automatically inserted and not yet checked. Please check the original and archive link according to the instructions and then remove this notice.  @1@ 2Template: Webachiv / IABot / www.linuxnetmag.org
  4. https://www.heise.de/ct/projekte/ct-Debian-Server-284111.html
  5. Article on the Project of the week at OSdir ( Memento of the original from December 27, 2015 in the Internet Archive ) Info: The archive link was automatically inserted and not yet checked. Please check the original and archive link according to the instructions and then remove this notice.  @1@ 2Template: Webachiv / IABot / www.osdir.com
  6. http://www.linux-magazin.de/heft_abo/ Ausgabe/2008/09/ offenes_gruen