Firewall Service/Winsock Redirector Service alternatives on Linux?

Firewall Service/Winsock Redirector Service alternatives on Linux?

Post by Nil Ein » Sat, 28 Feb 2004 02:25:46



Hey all,

Been searching ages for this and can't seem to find anything so I
suspect the answer is no but thought I might as well check since most
of what I found wasn't relevant.

I'm looking to replicate the 'Firewall service' in (MS) ISA server or
'Winsock Redirector service' found in Wingate. As you may know, these
are quite similar. Basically, they are proxies which have clients
(Firewall client/Wingate Internet client) which replace the winsock
DLLs on client computers and transparently redirect traffic as
necessary. What I'm looking for should either have it's own client for
Windows XP or if it uses one of the existing ones it might also work
although there might be legal issues.

I know of course about IP Masquerading (NAT) and socks proxies and
intend to use them. But I prefer the winsock redirector as my primary
method of access. I currently use Wingate and do sometimes use ENS
(NAT) and socks. I'm planning to move to Linux for my router (sharing
a modem connection with 3 computers) but although Qbik has been saying
they're going to deliver a Linux version of Wingate for ages, they
haven't yet.

If you're wondering what I like about the Winsock redirector is that
it's transparent and it works great for incoming and outgoing most of
the time. Of course, it does sometimes have problems. But that's
simply handled by telling WGIC to give the app local access only so it
uses ENS (NAT). Or alternatively, I can use socks. Either way, I
usually don't have to worry about port forwarding no matter what P2P
app I'm using. I use all sorts of stuff, games, many diff P2P apps etc
at various times so it can be a hassle if I have to rely on the app
supporting socks or set up port forwarding for each one when they need
(or prefer) incoming. And of course, NAT, while great for most apps
which don't need incoming, does have a few problems with somethings
sometimes so it's good to have the winsock redirector, at least as a
backup.

If there really is nothing I might have to just bite it but do hope
there is some Linux alternative.

Thanks all

 
 
 

Firewall Service/Winsock Redirector Service alternatives on Linux?

Post by Michael Heimin » Sat, 28 Feb 2004 03:16:06


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


> Hey all,
> Been searching ages for this and can't seem to find anything so I
> suspect the answer is no but thought I might as well check since most
> of what I found wasn't relevant.
> I'm looking to replicate the 'Firewall service' in (MS) ISA server or
> 'Winsock Redirector service' found in Wingate. As you may know, these
> are quite similar. Basically, they are proxies which have clients
> (Firewall client/Wingate Internet client) which replace the winsock
> DLLs on client computers and transparently redirect traffic as
> necessary. What I'm looking for should either have it's own client for
> Windows XP or if it uses one of the existing ones it might also work
> although there might be legal issues.

[..]

Quote:> If there really is nothing I might have to just bite it but do hope
> there is some Linux alternative.

The question is, what do you think iptables can't do for you? The
Linux firewalling/routing capabilities are state of the art, you
would need $$ equipment to get what some cheapo intel box running
any Linux distro, many download-able for free, can do for you.

If you are concerned about routing read the Advanced routing
HOWTO (www.tldp.org). There's AFAIK no other OS with this kind of
routing/Firewall features build directly in the kernel, so you
probably don't need any additional sw.
;)

- --
Michael Heiming - RHCE (GPG-Key ID: 0xEDD27B94)

Remove +SIGNS and www. if you expect an answer, sorry for
inconvenience, but I get tons of spam.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iD8DBQFAPjflAkPEju3Se5QRAgdMAJ9+twShXpmcxdMkjuiT9CWx0NbY9wCeIgZU
S+KCqrem344Pp4oe1BBpMy8=
=oXQ9
-----END PGP SIGNATURE-----