[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

Re: Best Hardware for TOR server..



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Scott Bennett wrote:
>      On Thu, 13 Dec 2007 08:31:43 +0100 Eugen Leitl <eugen@xxxxxxxxx>
> wrote:
>> On Wed, Dec 12, 2007 at 10:44:17PM -0800, algenon flower wrote:
>>
(snip)
>>
>>>    behind a  Linksys Firewall Router.
>> Make sure this is not your weak spot. OpenWRT is a good firmware here.
>> In general, it is always a good idea to buy a WRAP or ALIX (or its
>> Soekris equivalent) piece of kit, and flash it with a decent firewall,
>> like m0n0wall or pfSense.
> 
>      I've had problems with every Linksys router I've dealt with so far,
> but mainly with wireless service.  The built-in DHCP server, when presented
> with a request from a machine to which it has already issued a lease, fails
> to recognize that that machine is a current leaseholder and to issue it a
> copy of the existing lease.  Instead, it denies the request.  This is a
> worse problem for Windows than for FreeBSD in that Windows is far more
> likely to decide it has lost contact with a Linksys wireless router than
> FreeBSD is.
(snip)

My Linksys router is a wireless one - albeit with a custom firmware.
However, the machine running "kitsune" is hard-wired to its Ethernet
switches; I'd never run a service over a wireless link. IMHO, it's far
too flaky.

(Regardless, the WLAN is - of course - running WPA2-PSK/AES with a
63-character pseudorandom key, for my own piece-of-mind...)

>>>    **Comcast always adds their own modem, I am wondering if the usual
> 
>      Not necessarily so.  We saved a small amount per month by providing
> a modem and router ourselves.  Comcast's equipment was returned to them, and
> they stopped billing for it.
(snip)

Good point - I bought a modem outright, and I no longer pay a rental fee
(I've owned the router from day one). Well worth the investment, IMHO -
it'll pay for itself within a year, under many plans.

- --
F. Fox: A+, Network+, Security+
Owner of Tor node "kitsune"
http://fenrisfox.livejournal.com
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (MingW32)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFHYyvIbgkxCAzYBCMRAl9BAJ0W5AODjCblxidTSmvE/CqgpqUcbACfQNon
hBLH9yM+XOq16euR+e2GglA=
=GYO7
-----END PGP SIGNATURE-----