From owner-freebsd-embedded@FreeBSD.ORG Tue Mar 4 02:57:01 2008 Return-Path: Delivered-To: freebsd-embedded@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 5D4CD1065673 for ; Tue, 4 Mar 2008 02:57:01 +0000 (UTC) (envelope-from wblock@wonkity.com) Received: from wonkity.com (wonkity.com [67.158.26.137]) by mx1.freebsd.org (Postfix) with ESMTP id 298048FC13 for ; Tue, 4 Mar 2008 02:57:00 +0000 (UTC) (envelope-from wblock@wonkity.com) Received: from wonkity.com (localhost [127.0.0.1]) by wonkity.com (8.14.2/8.14.2) with ESMTP id m242Sm5i073028; Mon, 3 Mar 2008 19:28:48 -0700 (MST) (envelope-from wblock@wonkity.com) Received: from localhost (wblock@localhost) by wonkity.com (8.14.2/8.14.2/Submit) with ESMTP id m242SmKi073025; Mon, 3 Mar 2008 19:28:48 -0700 (MST) (envelope-from wblock@wonkity.com) Date: Mon, 3 Mar 2008 19:28:48 -0700 (MST) From: Warren Block To: Aaron Siegel In-Reply-To: <200803031807.53588.aj@siegel-tech.net> Message-ID: References: <200803031807.53588.aj@siegel-tech.net> User-Agent: Alpine 1.00 (BSF 882 2007-12-20) MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII; format=flowed X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-3.0 (wonkity.com [127.0.0.1]); Mon, 03 Mar 2008 19:28:48 -0700 (MST) Cc: freebsd-embedded@freebsd.org Subject: Re: Building my first gateway firewall with wireless support X-BeenThere: freebsd-embedded@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Dedicated and Embedded Systems List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 04 Mar 2008 02:57:01 -0000 On Mon, 3 Mar 2008, Aaron Siegel wrote: > My almost ten year old pc that has been running 24/7 as a firewall gateway is > about to die. (Of course it is running Freebsd) I would like to build a > embedded gateway, DNS server, with DDNS client, wireless access point, > IPSEC , and firewall. > > I appreciate some guidance, some helpfull links, or maybe share some of your > experiences. I hobbyist not a developer. I do not expect this to be easy. > > My dream access point would have two interfaces one protect by IPSEC vpn and > an unsecured (just a cheap linksys device connected to the LAN). The big > question how much processor power will I need to support one to ten clients? http://www.pfsense.org/ may be useful. -Warren Block * Rapid City, South Dakota USA