SYS-CON MEDIA Authors: Liz McMillan, Zakia Bouachraoui, Elizabeth White, Pat Romanski, Yeshim Deniz

Blog Feed Post

Open Source Firewalls - Untangle and pfSense comparison

So this week I had the opportunity of setting up a little lab to test both of these firewalls. Before this week I had no idea these firewalls even existed, and the only open source routing/firewall software I even knew of at the time was Vyatta; which is really only for routing purposes.

Starting off, you really need to pay attention to the system requirements, especially Untangles. I attempted to install both of these using Ubuntu with VirtualBox and was in for a nasty surprise. Originally skimming the requirements brought me to this issue, to where I used an old Dell Dimension 3000 box to use this on. Which as you may know, is very obsolete and moth-eaten. Lets just say the 1 GB of RAM and 40 GB hard drive didn't satisfy my general virtual needs; especially Untangles thirst for resources. So I decided to use ESX 3.5 on a beastly server that happened to be laying around; now we're talking.

Simply put, Untangle loves memory. There is no way around it, this is a Debian based OS that comes with its own pretty GUI; so you can see what I'm saying. But thats not just it, the tools on this thing are immensely creative. They are so creative that you need 2 GB of memory to run them properly. And thats if you only have a small amount of users. They say with 1-50 users you will be fine with 1 GB of memory but I highly recommend using more than that, who would not want to use more than 1 GB of memory anyways? Also, you will be fine with a Pentium 4 or equivalent processor until you hit 50+ users. Once your in the realm of that many users, you will want to be going dual core with 2 GB+ of memory. That will last you until 150 users, and well, you see where I'm going with this. This thing will handle up to 5000 users on a quad core, which I think is staggering. But are all these resources worth it? Absolutely!

Out of the box this thing will come with spam, phishing, spyware, and virus blockers. Not to mention its own Protocol Control which personally, is my favorite. Because it gives you a whole list (4 pages worth) of protocols to choose from, and take action on each. It has its own IPS as well, which has a good chunk of viruses/malware to choose from for blocking, with signatures included. And all of these tools are very straight forward with a friendly GUI. Almost anyone that has a basic understanding of networking and web application will be able to work with this fairly easily. There are a lot of other detailed tools as well, but I decided to briefly go over the ones that I found important.

Now unlike Untangle, pfSense is a FreeBSD OS. This firewall is very lightweight and has a pretty powerful terminal. Instead of needing a ton of memory and CPU power, this little guy can run comfortably on 128 MB of memory, and 300 MHz of CPU power, which is mainly for residential purposes. Once you reach 20-50 Mb throughput, you'll want a 500 MHz system with about 512 MB of memory. Still thats pretty lightweight if you ask me. 100 Mb wire-speed? Eh, no problem, just push your CPU power to about 700 MHz to 1 GHz, this thing operates effortlessly.

Administering pfSense can only be done from the Webui, locally you have the terminal, which is very helpful in setting up the box. Once your in the Webui, theres a few wizards to help you to get started. You really need to dig in order to find some of the nifty tools, in the start it doesn't throw them all at your face for ease of use like Untangle does. The blocking is mostly done through a rule base inside the Webui, which I started to like a lot. But unlike Untangle, you need to start from scratch on all the blocking/passing, whereas Untangle gives you about 4 pages worth of different protocols and web categories to block/pass that have signatures already in place.

The available services for pfSense are also pretty nifty. You can set up your own PPPoE server, OpenNTPD server, and you can even enable RIP on your network, among others, and VPN setup seems fairly easy.

I personally think Untangle is the best to get started on for a beginner. The GUI is very helpful and directive on what you should do. I personally liked the web filter and how it gave description of everything you selected, that can be very helpful if you are unsure. PfSense requires you to build everything from scratch, its way more advanced versus Untangle; but this also gives you a lot more control. However, the performance of pfSense while being so lightweight is unbeatable. Especially if you aren't looking to spend a lot of money on hardware. All in all, it comes down to personal preference.

Read the original blog entry...

More Stories By Hurricane Labs

Christina O’Neill has been working in the information security field for 3 years. She is a board member for the Northern Ohio InfraGard Members Alliance and a committee member for the Information Security Summit, a conference held once a year for information security and physical security professionals.

Latest Stories
"There is a huge interest in Kubernetes. People are now starting to use Kubernetes and implement it," stated Sebastian Scheele, co-founder of Loodse, in this SYS-CON.tv interview at DevOps at 19th Cloud Expo, held November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA.
Kubernetes is an open source system for automating deployment, scaling, and management of containerized applications. Kubernetes was originally built by Google, leveraging years of experience with managing container workloads, and is now a Cloud Native Compute Foundation (CNCF) project. Kubernetes has been widely adopted by the community, supported on all major public and private cloud providers, and is gaining rapid adoption in enterprises. However, Kubernetes may seem intimidating and complex ...
Dito announced the launch of its "Kubernetes Kickoff" application modernization program. This new packaged service offering is designed to provide a multi-phased implementation and optimization plan for leveraging Kubernetes on Google Kubernetes Engine (GKE). Kubernetes, a relatively new layer of the modern cloud stack, is a production-ready platform that allows companies to deploy and manage containerized applications, update with zero downtime, and securely scale their deployments.
The use of containers by developers -- and now increasingly IT operators -- has grown from infatuation to deep and abiding love. But as with any long-term affair, the honeymoon soon leads to needing to live well together ... and maybe even getting some relationship help along the way. And so it goes with container orchestration and automation solutions, which are rapidly emerging as the means to maintain the bliss between rapid container adoption and broad container use among multiple cloud host...
In his general session at 19th Cloud Expo, Manish Dixit, VP of Product and Engineering at Dice, discussed how Dice leverages data insights and tools to help both tech professionals and recruiters better understand how skills relate to each other and which skills are in high demand using interactive visualizations and salary indicator tools to maximize earning potential. Manish Dixit is VP of Product and Engineering at Dice. As the leader of the Product, Engineering and Data Sciences team at D...
The KCSP program is a pre-qualified tier of vetted service providers that offer Kubernetes support, consulting, professional services and training for organizations embarking on their Kubernetes journey. The KCSP program ensures that enterprises get the support they're looking for to roll out new applications more quickly and more efficiently than before, while feeling secure that there's a trusted and vetted partner that's available to support their production and operational needs.
Serverless Architecture is the new paradigm shift in cloud application development. It has potential to take the fundamental benefit of cloud platform leverage to another level. "Focus on your application code, not the infrastructure" All the leading cloud platform provide services to implement Serverless architecture : AWS Lambda, Azure Functions, Google Cloud Functions, IBM Openwhisk, Oracle Fn Project.
Modern software design has fundamentally changed how we manage applications, causing many to turn to containers as the new virtual machine for resource management. As container adoption grows beyond stateless applications to stateful workloads, the need for persistent storage is foundational - something customers routinely cite as a top pain point. In his session at @DevOpsSummit at 21st Cloud Expo, Bill Borsari, Head of Systems Engineering at Datera, explored how organizations can reap the bene...
As you know, enterprise IT conversation over the past year have often centered upon the open-source Kubernetes container orchestration system. In fact, Kubernetes has emerged as the key technology -- and even primary platform -- of cloud migrations for a wide variety of organizations. Kubernetes is critical to forward-looking enterprises that continue to push their IT infrastructures toward maximum functionality, scalability, and flexibility.
DevOps has long focused on reinventing the SDLC (e.g. with CI/CD, ARA, pipeline automation etc.), while reinvention of IT Ops has lagged. However, new approaches like Site Reliability Engineering, Observability, Containerization, Operations Analytics, and ML/AI are driving a resurgence of IT Ops. In this session our expert panel will focus on how these new ideas are [putting the Ops back in DevOps orbringing modern IT Ops to DevOps].
At CloudEXPO Silicon Valley, June 24-26, 2019, Digital Transformation (DX) is a major focus with expanded DevOpsSUMMIT and FinTechEXPO programs within the DXWorldEXPO agenda. Successful transformation requires a laser focus on being data-driven and on using all the tools available that enable transformation if they plan to survive over the long term. A total of 88% of Fortune 500 companies from a generation ago are now out of business. Only 12% still survive. Similar percentages are found throug...
Intel is an American multinational corporation and technology company headquartered in Santa Clara, California, in the Silicon Valley. It is the world's second largest and second highest valued semiconductor chip maker based on revenue after being overtaken by Samsung, and is the inventor of the x86 series of microprocessors, the processors found in most personal computers (PCs). Intel supplies processors for computer system manufacturers such as Apple, Lenovo, HP, and Dell. Intel also manufactu...
Serverless applications increase developer productivity and time to market, by freeing engineers from spending time on infrastructure provisioning, configuration and management. Serverless also simplifies Operations and reduces cost - as the Kubernetes container infrastructure required to run these applications is automatically spun up and scaled precisely with the workload, to optimally handle all runtime requests. Recent advances in open source technology now allow organizations to run Serv...
GCP Marketplace is based on a multi-cloud and hybrid-first philosophy, focused on giving Google Cloud partners and enterprise customers flexibility without lock-in. It also helps customers innovate by easily adopting new technologies from ISV partners, such as commercial Kubernetes applications, and allows companies to oversee the full lifecycle of a solution, from discovery through management.
In his session at 20th Cloud Expo, Mike Johnston, an infrastructure engineer at Supergiant.io, will discuss how to use Kubernetes to setup a SaaS infrastructure for your business. Mike Johnston is an infrastructure engineer at Supergiant.io with over 12 years of experience designing, deploying, and maintaining server and workstation infrastructure at all scales. He has experience with brick and mortar data centers as well as cloud providers like Digital Ocean, Amazon Web Services, and Rackspace....