Home security setup - help pls!

Dear Community,

I’m looking for a simple solution that can do firewall, IPS, DNS caching and filtering (like pi-hole or adguard home), plus NAT and DHCP. I want to know if IPFire can do all this and which devices work best with it.

My plan is to buy a device that fits between the ISP’s router and my home switch to handle these tasks.

Thanks for your help!

Viktor

Hi Viktor,

thank you for asking!

IPFire can do all the things you mentioned. Feel free to read more in our documentation at www.ipfire.org - Welcome to IPFire Documentation. Especially this page could be handy for you: www.ipfire.org - Firewall Documentation

The devices working best with IPFire are the ones we make ourselves. You can find them at Lightning Wire Labs - the company behind IPFire: Firewall Appliances - Lightning Wire Labs Store.

Best,
Rico

Hi Victor,

one thing you should think about is to ‘switch your ISP router to a media converter(modem)’ only, if possible.
This reduces problems with NAT and DNS/firewalling. My experience is, that in this configuration the administration and problem solution is much easier.

Welcome Viktor,

In response to your capabilities question:

Firewall -yes
IPS - yes
DNS caching and filtering - yes
NAT - yes
DHCP - yes

Another thing that you’ll find with IPFire is that if you have problems with installation, configuration or other issues, the community here is very active and helpful and responds pretty quickly to questions that you may have about using IPFire!

To me that’s a big plus for choosing to use IPFire!

Regards,
Stephen

IpFire can do quite everything you’re looking for (IMO the DNS filtering is a bit on the small size) however is not… Simple.

While not being that hard to use, configure, manage, the whole software expects you to “know your shill”, in networking design, configuration, rule creation.

There’s a setup procedure, there is documentation, but there are no safety nets or guardrails to avoid that you mess so much the configuration that maybe 5 minutes ago was “quite good but not enough”.

Using other words, is no consumer-ready project at all.

On the brighter side, could teach you a lot. If you not willing to learn and/or spend time, consider to pay someone that kickstart your goals in somewhat working configuration.

What products that provide similar functionality to IPFire have anything approaching “guardrails”? None.

And as for the implication of versioning, of course we can save a configuration and restore.

Hi @johnh ,
you’re correct on both statements.

However, I dont’t know at all @viktorioannou, neither is familiarity with this kind of software or network skill.
So, at best of my capabilities in that moment while being brief in wording and contained in time of writing, I tried to provide some “good enough answer” to describe something that IpFire can do for his use.

Maybe he’s a skilled, experienced and crafty network admin, maybe he’s not. I don’t know. But while still considering IpFire unsuitable firewall distro for my uses, I think that he can deburr his knowledge using it and… teaching himself something useful.
Like everyone will read his post and my answer.

@pike_it , you are right. IPFire never tried to be a ‘user ready’ solution, with defining user=everybody.
A ‘user ready’ SW sets policies defined by some ‘experts’. Because it doesn’t rely on experience and skills of the end user, those solutions even do not document the functionality implemented. Use it or leave it.
IPFire is designed as a well chosen framework for implementing an internet access appliance. The basic configuration is documented more or less well. Expansions can be realised by users with the special knowledge. But in both cases ( basic or expert ) you must know what such a network device does and how the functionality is achieved. Means without basic knowledge of networking and firewalling you are lost.

We were all beginners once.

When I started out with IPCop and later IPFire, I didn’t have in-depth knowledge of Linux, DNS, DHCP, firewall rules, logs, and so on.
And I learned a great deal simply by using these tools and with the help of the community.

Admittedly, Lightning Wire Labs offers a professional solution and support service, which is very useful for those who need it.

But, without knowing Viktor personally, I would say that IPFire can run on fairly basic hardware. An old PC or a mini-PC with two network cards is enough to get started.

And as @stephen rightly points out, the community is ready to answer his questions.

In terms of the device you’re looking for, you might have a look at my post on the very small Wyse 5070 system.