[Asterisk-Users] Firewall will definately increase jitters inyourvoice conversation

Chris Travers chris at metatrontech.com
Sat Aug 13 15:17:34 MST 2005


Rich Adamson wrote:

>That's a crack of crap sold by the marketing (not sales) people selling
>firewalls. "If" you know what you're doing, one can very easily secure any
>linux system to function on the Internet (etc) without a firewall. It all
>depends on your level of knowledge/skills on how to disable those items
>that are not really needed in your environment. Start with a 'netstat -a'
>to identify those ports that are listening, and shut those items down that
>you don't want exposed.
>
>You "can" do the same for any MS system as well.
>
>  
>
But you still want a firewall here especially if you have several VOIP 
systems which could be making independent connections to the internet.  
The firewall in this case will hopefully not only do things like VPN for 
securing your data in trasit between your office and a remote one, but 
it will also provide a platform for QoS/traffic shaping.  To avoid the 
firewall here is actually *asking* for sound quality problems in 
addition to the fact that you no longer have the entrence point to your 
network secured.

Now to your point....  Almost any Linux system can be configured (if you 
know what you are doing) to perform all these firewalling functions.  
Just add an extra network card, put it on the perimeter of your network, 
set up iptables, traffic shaping, uninstall unnecessary software, use 
Netstat to doublecheck listening ports, etc. and you have your 
firewall.  A firewall doesn't have to be expensive but some form of 
perimiter control is very helpful in these cases.

Best Wishes,
Chris Travers
Metatron Technology Consulting
-------------- next part --------------
A non-text attachment was scrubbed...
Name: chris.vcf
Type: text/x-vcard
Size: 127 bytes
Desc: not available
Url : http://lists.digium.com/pipermail/asterisk-users/attachments/20050813/572404e2/chris.vcf


More information about the asterisk-users mailing list