Technical Discussion
  >> DSL Hardware Discussion


Register (or login) on our website and you will not see this ad.


Pages in this thread: 1 | [2] | (show all)   Print Thread
Standard User BatBoy
(sensei) Thu 24-Nov-16 21:21:31
Print Post

Re: Modem/router for FTTC dualstack IPv6/v4


[re: RobertoS] [link to this post]
 
I see it in the opposite way, security by obscurity is worse than no security at all.
Standard User David_W
(knowledge is power) Thu 24-Nov-16 22:03:12
Print Post

Re: Modem/router for FTTC dualstack IPv6/v4


[re: BatBoy] [link to this post]
 
In reply to a post by BatBoy:
I see it in the opposite way, security by obscurity is worse than no security at all.
I agree. Other strengths of open source is that users can fix issues they find themselves if they have the necessary skills, also there is less chance of being stuck on an obsolete version with known security holes because of financial reasons or cessation of vendor support. That said, pfSense is going to drop support for the i386 platform (Intel 32 bit) in the near future, as there are few still-worthwhile hardware devices that will not run in 64 bit mode.


Part of the strength of pfSense is that it is built using well-regarded open source foundations:

Operating system: FreeBSD
Firewall and traffic shaper: pf (which FreeBSD committers have ported from OpenBSD to FreeBSD)
IPsec: the FreeBSD IPsec kernel code (based on KAME and OpenBSD code) and strongSwan IKE daemon
OpenVPN: the reference implementation
PPP: FreeBSD kernel netgraph with the mpd 5 userland daemon handling ancillary tasks
Web server: nginx (in recent version of pfSense)
Responsive UI (pfSense 2.3 onwards): Bootstrap
Modularisation / upgrade handling (pfSense 2.3 onwards): FreeBSD pkg


The 'glue' code is pfSense is PHP and was originally forked from monowall. This is of variable quality and does not follow best practice on privilege separation or modularisation. These issues are typical of software products that have evolved rather than being a clean implementation of an engineered solution. The intention is to rewrite the entire system in python with clear and rigidly enforced client/server separation. As the configuration is held in a single XML file, upgrades between versions or even across technologies are easy to implement.

Any risks from the current glue code are mitigated by the good quality firewall implementation and the strong suggestion that the user interface is not made externally accessible. If remote management is needed, a VPN can be used to gain access to a local network with access to the user interface.


I have high regard for many commercial products, including those from Draytek and Cisco, but you have to take much more about code quality on trust in a closed source product.



ZeN Unlimited Fibre 2 with native IPv6
thinkbroadband speed test : speedtest.net : thinkbroadband quality monitor IPv4 IPv6
Standard User RobertoS
(elder) Fri 25-Nov-16 13:50:54
Print Post

Re: Modem/router for FTTC dualstack IPv6/v4


[re: RobertoS] [link to this post]
 
As most discussion on FTTC modem/routers has occurred in the past in the Fibre Broadband forum I have reposted there including caffn8me's and Michael_Chare's replies.

I've asked for this thread to be locked as new contributors in this forum seem unlikely, particularly in view of the digression that I am not interested in. Anyone who can help, please reply in the new thread, thanks.

Kindness isn't going to cure the world of all its awfulness but it's a good place to begin. Daisy Ridley.
My broadband basic info/help site - www.robertos.me.uk. Domains, site and mail hosting - Tsohost.
Connection - AAISP Home::1 80/20. Sync 60000/14463kbps @ 600m. - BQM


Register (or login) on our website and you will not see this ad.

Pages in this thread: 1 | [2] | (show all)   Print Thread

Jump to