Might I suggest using something like Untangle (http://www.untangle.com). Very good with content filtering, Can run as its own server or as a windows based app.
A linux PC as started earlier you would have problems with Content &
Application Filtering which you can use Dansquardian and port
filtering.For loadbalancing suggest you use BalanceNG.OpenVPN for VPN
finally you have your iptables and Snort for the firewall and IPS and
you can set up a DMZ if you want to access the 5 or so Comps
remotely...
PS:All this ca be used on Ubuntu platform...
On 8/6/09, Jamal Mohamed <jamal.worx@gmail.com> wrote:
> I would suggest you go for a mikrotik, it does all of the above but not so
> sure bout the IPS.It's cheaper than other routers and most of all based on
> GNU/Linux.Or you can get to install in a x86 box and power xen to run other
> stuff for you.
>
> On Thu, Aug 6, 2009 at 6:30 PM, Steve Muchai <smuchai@gmail.com> wrote:
>
>> lemme add to Wash's take, inline....
>>
>>
>> 2009/8/5 Joe Murithi Njeru <joe.njeru@gmail.com>:
>> > Hi Odiambo,
>> >
>> > Yes detection & prevention must come together.
>> >
>>
>> IDS - Snort.
>> IPS - psad - http://cipherdyne.org/psad/. Used this combination before
>> and works great.
>>
>> BR,
>> S
>> _______________________________________________
>> Skunkworks mailing list
>> Skunkworks@lists.my.co.ke
>> http://lists.my.co.ke/cgi-bin/mailman/listinfo/skunkworks
>> Other services @ http://my.co.ke
>> Other lists
>> -------------
>> Announce:
>> http://lists.my.co.ke/cgi-bin/mailman/listinfo/skunkworks-announce
>> Science: http://lists.my.co.ke/cgi-bin/mailman/listinfo/science
>> kazi: http://lists.my.co.ke/cgi-bin/mailman/admin/kazi/general
>>
>
_______________________________________________
Skunkworks mailing list
Skunkworks@lists.my.co.ke
http://lists.my.co.ke/cgi-bin/mailman/listinfo/skunkworks
Other services @ http://my.co.ke
Other lists
-------------
Announce: http://lists.my.co.ke/cgi-bin/mailman/listinfo/skunkworks-announce
Science: http://lists.my.co.ke/cgi-bin/mailman/listinfo/science
kazi: http://lists.my.co.ke/cgi-bin/mailman/admin/kazi/general