VMware

Fireball ISO Builder 1.1

Appliance Type

Community

Description

Features in the generated ISO

  • IPv4 support (of course!)
  • IPv6 support
  • (optional) tunneled IPv6 access for entire network to the Internet - requires free account with go6.net (also known as Freenet) tunnel broker
  • iptables and ip6tables firewalls
  • SSH server for full command-line access
  • DNS Cache
  • DHCP server
  • tcpdump & other networking utilities
  • Perl and Python scripting languages
  • Nano text editor
  • Ntp client
  • DSL support
  • Low hardware requirements: Pentium computer with CD-ROM capable of booting, and two network interface cards. No hard disk, monitor, keyboard, required (though a monitor and keyboard might be useful for troubleshooting configurations as needed).

The virtual appliance can be updated just like a normal Gentoo system, allowing new images to be generated with security and other bug fixes, additional features, and updated configurations.

Features & Benefits

Fireball ISO Release 1.1 (6/22/2009) Changes:

  • Many updates included - kernel, iptables, sshd, other software
  • Base environment now runs ntpd at boot, in order to keep the time accurate. However, in the build environment (what eventually becomes the generated ISO image), the time is updated hourly with ntpdate, from servers listed in /etc/ntp.conf. If you're comfortable with running ntpd on your firewall server, you can always replace the hourly ntpdate with ntpd for slightly better accuracy (tenths or hundredths of a second, so not much better unless your hardware clock is pretty bad).
  • Updated freenet6 (gw6c) to the renamed package gateway6, and placed server keys in /var/lib/gateway6. The IPv6 tunnel isn't started by default, in case you don't use it; see docs for how to start it on boot, as well as how to enable the new monitoring/restart script.
  • Masked >=sys-fs/squashfs-tools-4.0 for now, since it causes problems with newer kernels (so only version 3.3 of squashfs-tools is installed) - you can remove this from /etc/portage/package.mask if you'd like to update it when this is no longer an issue.
  • Tweaks made to IPv4 & IPv6 firewall rules. Of course, these need to be evaluated and modified for your network.

Indy

Pricing

Free

Tags & Keywords

firewall, linux, ipv4, ipv6, gentoo, iso, bootable, livecd, cd

Solution Categories

Networking, Secure Content and Threat Management