Answer the question
In order to leave comments, you need to log in
Which system to choose for the gateway?
Hello. Help me choose a system that would be suitable for the following tasks. Thanks in advance.
Answer the question
In order to leave comments, you need to log in
I have FreeBSD 10.2:
support for the main and backup Internet channelAlmost implemented, the hands did not reach the weekend to work pancake at night. And so the MTS modem picked up, the connection is established. It's just that I need to cut the backup channel with handles and edit some configs (in the local dns unbound, in particular) when switching to a modem.
support for usb modems
working in a virtual machineI don’t have a graphical shell at all, everything is through the command line .. I don’t know how to raise a virtual wheelbarrow ....
web interfaceFor the sqstat proxy and some other "a la stat for a squid" - for them I raised Apache, a muscle, I looked at the status from the local network via the web interface.
transparent proxy including httpsJudging by the articles, squid 3.5.8 primarily rolls - transparent https proxying without changing certificates, I can say that I tried a bunch of the latest versions, I didn’t try 3.5.8 ... It works - it works, but when 5+ users go online - https puts squid, https starts to slow down a lot... According to Nagibator's articles, only 3.5.8 rolls - his articles on Habré for debian:
on-the-fly virus scanXs .. if you check the virus for all incoming outgoing traffic, and for viruses for Windows .. xs .. dr.web happens for Fryakha (paid). And on Fryakha herself - what viruses ... Fire, etc. decide.
authorization of users from ADHey, I don't have a domain
free+
openvpn supportI don't know, but I'm sure it's not a problem for Fryakha.
you can attach existing certificates to itWell, there is something in Squid, creation of serts... I don't know...
creating custom firewall rules through the web interfaceIn PfSense, this is how it is done anyway. I write the ipfw config by hand.
user traffic countSo it has not been implemented. Although while Squid was working, it was SqStat that was collecting on the web face - who downloaded it and from where.
intrusion detectionRegular log. By keywords, you set up search and alerts. Let's just say that I don't monitor unsuccessful attempts to enter the gateway, since there are a lot of them (robots regularly try standard logins-passes), but accepted - there is a separate notification.
online monitoring of traffic by clients (you need to determine who is loading the channel at the moment)iftop does an excellent job, a small config for it has 5-7 lines of parameters, and monitors everything online, I regularly use it to cut "bad" ones. At the same time, settings and filters are very flexible online in the process of monitoring.
content filtering including https by usersIn Squid, the above works perfectly, but in the case of https, it will not be possible to set up a page for the user ... it will just be a browser message "Failed to load page". And so in Squid everything is flexible - both in terms of content and sites (not by their ip or dns - namely by domain names) both for groups and for individual users. "Everything is allowed except" or "Everything is forbidden except" ... whatever.
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question