Release of the IPFire 2.23 distribution for creating firewalls

Created release of the distribution for creating routers and firewalls — IPFire 2.23 Core 131. IPFire features an extremely simple installation process and configuration organization through an intuitive web interface filled with visual graphs. The installation size ISO image is 256 MB (x86_64, i586, ARM).

The system is modular; in addition to basic functions of packet filtering and traffic management, IPFire offers modules for implementing Suricata-based attack prevention systems, creating file servers (Samba, FTP, NFS), mail servers (Cyrus-IMAPd, Postfix, Spamassassin, ClamAV, and Openmailadmin), and print servers (CUPS), setting up a VoIP gateway based on Asterisk and Teamspeak, creating a wireless access point, and organizing audio and video streaming servers (MPFire, Videolan, Icecast, Gnump3d, VDR). A special package manager, Pakfire, is used for installing add-ons in IPFire.

In the new release:

  • A new intrusion prevention system (IPS) has been introduced, supporting deep packet inspection mode and providing potential threat identification. The system is based on the developments of the project Suricata and differs from the previously offered IPS based on Snort with higher performance and security. Old IPS settings will automatically be converted after upgrading IPFire, but by default, after migration, the IPS runs in monitoring mode and requires manual adjustment of settings to switch to packet filtering mode. The guardian add-on is no longer required for ISP operation, but it can be used separately to block SSH password guessing attempts;
  • System components have been updated, using Linux kernel 4.14.113, gnutls 3.6.7.1, lua 5.3.5, nettle 3.4.1, ntp 4.2.8p13, rrdtool 1.7.1, unbound 1.9.1;
  • Support for redirecting requests through SSH Agent has been added, allowing the host with IPFire to be used as an intermediary for connecting to hosts in the internal network;
  • Updated packages with add-ons: borgbackup 1.1.9, dnsdist 1.3.3, freeradius 4.0.18, nginx 1.15.9, postfix 3.4.5, zabbix_agentd 4.2.0;
  • A separate set of rules for filtering outgoing traffic (TOR_OUTPUT) directed through the Tor gateway has been implemented for Tor.
  • The implementation of the wireless access point has added an isolation mode that allows blocking interaction between clients connected to the wireless network;
  • A new flashrom package has been added with a utility for updating firmware.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster