Wilders Security Forums  

Go Back   Wilders Security Forums > Software, Hardware and General Services > all things UNIX
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old May 27th, 2012, 01:46 AM
Mouzer Mouzer is offline
Infrequent Poster
 
Join Date: May 2012
Posts: 6
Default Tightly secured unix distr. needed for VPN

I'm currently using a VPN service but i'd like to setup my own VPN server.

What i'm looking for is a unix distr. that doesn't come with a lot of packages and is secure by itself. I don't want to have anything running on the unix server except SSH, OpenVPN and a good firewall/iptables.

My knowledge about Unix is very little but i really want to do this myself.

Hope to hear some recommendations.

Thank you.
  #2  
Old May 27th, 2012, 04:25 AM
mirimir mirimir is offline
Very Frequent Poster
 
Join Date: Oct 2011
Posts: 1,524
Default Re: Tightly secured unix distr. needed for VPN

You might consider pfSense. That's FreeBSD + OpenVPN and a few other packages.
  #3  
Old May 27th, 2012, 05:00 AM
mack_guy911's Avatar
mack_guy911 mack_guy911 is offline
Very Frequent Poster
 
Join Date: Mar 2007
Posts: 2,483
Default Re: Tightly secured unix distr. needed for VPN

http://www.wilderssecurity.com/showthread.php?t=324873
__________________
Scientific Linux 6.2, xubuntu 11.10 *2x, Linux mint 10, Linux mint 12, opensuse 11.4, windows vista, ubuntu 10.04 and windows xp
  #4  
Old May 27th, 2012, 06:29 AM
Ranget's Avatar
Ranget Ranget is offline
Frequent Poster
 
Join Date: Mar 2011
Location: Not Really Sure :/
Posts: 832
Default Re: Tightly secured unix distr. needed for VPN

what about LPS ? it has vpn function and it's supposed to be secure
__________________
Spyshelter Premuim + MBAM Pro +Avast Free + Hardend FireFox + Secunia Update Checker
"Uncommon sense will increase your privacy; common sense will just make you common."
"The Worst Thing in the World is To look and not be able to Help "
  #5  
Old May 27th, 2012, 05:47 PM
BrandiCandi
 
Posts: n/a
Default Re: Tightly secured unix distr. needed for VPN

Nothing is going to be secure out of the box. You'll have to do some configuring no matter what. But take a look at this:

http://engardelinux.org/modules/index/index.cgi

Which has a lot of built-in features to increase security.

Edit: Whoops- I failed to notice the "VPN" part of your post. I don't know if this would work as a VPN.

Last edited by BrandiCandi : May 27th, 2012 at 05:53 PM.
  #6  
Old May 28th, 2012, 05:47 AM
mack_guy911's Avatar
mack_guy911 mack_guy911 is offline
Very Frequent Poster
 
Join Date: Mar 2007
Posts: 2,483
Default Re: Tightly secured unix distr. needed for VPN

out of box are

untangle

astaro security gateway (which i feel best)

clearOS ( base of centos server/gateway)

zentyal ........ etc many more )
__________________
Scientific Linux 6.2, xubuntu 11.10 *2x, Linux mint 10, Linux mint 12, opensuse 11.4, windows vista, ubuntu 10.04 and windows xp
  #7  
Old June 15th, 2012, 09:33 AM
Mouzer Mouzer is offline
Infrequent Poster
 
Join Date: May 2012
Posts: 6
Default Re: Tightly secured unix distr. needed for VPN

Quote:
Originally Posted by mirimir
You might consider pfSense. That's FreeBSD + OpenVPN and a few other packages.

How hard is it to start using that distro without any experience with FreeBSD?
  #8  
Old June 15th, 2012, 09:34 AM
Mouzer Mouzer is offline
Infrequent Poster
 
Join Date: May 2012
Posts: 6
Default Re: Tightly secured unix distr. needed for VPN

Quote:
Originally Posted by Ranget
what about LPS ? it has vpn function and it's supposed to be secure

I will look into it, thank you.
  #9  
Old June 15th, 2012, 09:35 AM
Mouzer Mouzer is offline
Infrequent Poster
 
Join Date: May 2012
Posts: 6
Default Re: Tightly secured unix distr. needed for VPN

Quote:
Originally Posted by BrandiCandi
Nothing is going to be secure out of the box. You'll have to do some configuring no matter what. But take a look at this:

http://engardelinux.org/modules/index/index.cgi

Which has a lot of built-in features to increase security.

Edit: Whoops- I failed to notice the "VPN" part of your post. I don't know if this would work as a VPN.

Thanks, but i have read somewhere engarde hasn't been updated since 2008.
  #10  
Old June 15th, 2012, 09:37 AM
Mouzer Mouzer is offline
Infrequent Poster
 
Join Date: May 2012
Posts: 6
Default Re: Tightly secured unix distr. needed for VPN

Quote:
Originally Posted by mack_guy911
out of box are

untangle

astaro security gateway (which i feel best)

clearOS ( base of centos server/gateway)

zentyal ........ etc many more )

Thanks.

Isn't untangle just a firewall package? And it's GUI no console, right?

I will look into the others. ClearOS might be interesting, i do have a bit of experience with CentOS.
  #11  
Old June 15th, 2012, 09:39 AM
Mouzer Mouzer is offline
Infrequent Poster
 
Join Date: May 2012
Posts: 6
Default Re: Tightly secured unix distr. needed for VPN

So once i have chosen a distribution, what should i do?

- Configure IPtables (any good script around to block EVERYTHING except SSH and OpenVPN?)
- Intrusion detection?
- File modification detection?
- Should i enable SELinux (if available?)
- Any other security recommendations?

The server will only run SSH+openvpn.
  #12  
Old June 15th, 2012, 12:07 PM
mack_guy911's Avatar
mack_guy911 mack_guy911 is offline
Very Frequent Poster
 
Join Date: Mar 2007
Posts: 2,483
Default Re: Tightly secured unix distr. needed for VPN

i never used VPN so didnt say much but yes untange you can configure as VPN server so with astaro please check forums they support open VPN

and clearOS and zentyal are very much server base also you can see PFsense (base of BSD) it also support VPN service and right and secure distro

they are more them just router they support many things

http://forums.untangle.com/openvpn/1...l-openvpn.html

http://wiki.untangle.com/index.php/OpenVPN

guess it help
__________________
Scientific Linux 6.2, xubuntu 11.10 *2x, Linux mint 10, Linux mint 12, opensuse 11.4, windows vista, ubuntu 10.04 and windows xp
  #13  
Old June 15th, 2012, 06:02 PM
BrandiCandi
 
Posts: n/a
Default Re: Tightly secured unix distr. needed for VPN

Quote:
Originally Posted by Mouzer
The server will only run SSH+openvpn.
If that's all you're running on it, why don't you just install those on a desktop? Why have an entire server running for just those two services?

As for configuring them, most distros have wikis or how-tos which will give you details on how best to configure each service.
  #14  
Old June 20th, 2012, 04:28 PM
Fox Mulder Fox Mulder is offline
Regular Poster
 
Join Date: Jun 2011
Posts: 182
Default Re: Tightly secured unix distr. needed for VPN

I might be a little late to the party, but I use Debian for all my server needs. It's light, secure, and you can always find documentation for whatever you want to do. It's all-around a very good OS.

It comes with few features pre-installed if you want to do a bare bones install, which is good as it reduces the attack surface of your server.
__________________
Windows 8 Pro x64

First Line of Defense: Sandboxie for Internet-facing programs, Privatefirewall
Hardening: EMET, Early Launch Anti-Malware Enabled
Browser: Google Chrome (ScriptNo, Adblock)
Scanning: MBAM Pro, Windows Defender
 

Wilders Security Forums > Software, Hardware and General Services > all things UNIX « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 05:50 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums