|
|
|
|
|
by vonskippy
4305 days ago
|
|
Rolling your own firewall is almost always a bad idea. Hardening a full blown distro is a terrible place to start, and no place for a novice to "guess" that they have it locked down "enough". There are numerous open source firewall distro's that have the advantage of being authored by people well practiced in security coding, pen testing, etc, and are continually crowd tested for loopholes and shortcomings. It's your edge device for security - not exactly a place you want to take risks with. |
|
I appreciate the level of specific engineering that goes into purpose-built firewall distros, but "locking down" a device whose sole function is to perform NATing for a network is not terribly complicated.