IPCop 1.4.1 review
Although device support is limited, IPCop is deceptively simple yet powerful firewall software that is a cinch to install, easy to use and delivers very good reporting facilities.
Review Date: 20 Jan 2005
Reviewed By: Dave Mitchell
Price when reviewed: download
The best things in life are free, goes the saying, and this can be applied just as well to firewalls. Many companies, including small businesses, can pay a fortune for network security and yet sometimes the simplest and most cost-effective solutions are right under their noses.
The IPCop project is a collaboration, the mission of which is, quite simply, to produce the best Linux-based firewall, primarily for home users and small businesses. The software is freely available for download, but the IPCop team accepts no monetary donations. Instead, it asks, where possible, for coding skills, time and hardware to be donated to help the project. Installation starts by downloading the appropriate ISO image and burning a bootable CD. Load this into your donor system, answer a few simple questions and five minutes later your firewall is ready to go.
IPCop supports both IDE and SCSI hard disks, although we did encounter driver-related problems installing on the latter and opted to go for the former for testing. There's no real need for SCSI anyway, as IPCop's demands on disk usage are minimal. Next you add an IP address for the LAN and then remotely connect to your new appliance via a browser. This version will now automatically switch you over to an HTTPS session.
IPCop supports LAN and WAN connections. It can use extra network adaptors for DMZ (demilitarized zone) and wireless ports as well, although these must all be set up during the installation phase. The WAN connection also supports PSTN, ISDN and ADSL modems, but check out the website first, as limited device support is probably IPCop's biggest weakness.
The browser interface is well designed and simple to use. The System tab provides swift access to configuration backup facilities, password settings and a page that advises of any new updates, as well as providing facilities for downloading and applying them. From the Services tab, you can activate web proxy and cacheing features, decide on how much disk space the latter can use and whether to limit the size of file transfers. Along with many appliance vendors, IPCop uses the open-source Snort for intrusion detection and you can download new attack rules directly into the appliance. It also supports VPNs and offers basic traffic-shaping functions where you can prioritise services based on port numbers.
Where IPCop scores heavily over typical dumb NAT firewall boxes is with its high levels of operational information. Most low-cost security appliances have virtually no reporting facilities, so you've no idea if they're handling the load or whether you've been subjected to an attack. IPCop's firewall logs provide a wealth of information about each attack and where it's coming from.
The Status tab also keeps you well informed about system memory and disk resources, plus all services. There are plenty of graphs showing resource usage and all network activity on each configured interface. A connection tracker also keeps a record of all source and destination IP addresses in a table colour coded for each interface.
No doubt there are people who pour scorn on these kinds of projects, but make no mistake, IPCop is good - very good. We have no qualms about recommending IPCop, as we were impressed with it during testing and have seen it being used in SME environments by very happy administrators.
Author: Dave Mitchell
- EU warns Nokia not to become a "patent troll"
- Police knock out 40 sites accused of piracy
- Government broadband chief defends fibre rollout
- Samsung launches 1TB SSD for Ultrabooks and tablets
- Fibre sells out within hours in area BT said "wasn't commercially viable"
- iBeacon: Apple finds a new way to annoy shoppers via their iPhones
- Top tech firms tell Obama: surveillance has gone too far
- Second NatWest outage in a week after DDoS attack
- Ex-Microsoft exec Paul Maritz "too old" to do Ballmer's job
- Microsoft patches TIFF flaw in next Patch Tuesday
- Switching from iPhone to Android: what I miss, what I don't
- Tech City: Easy to score when you move the goalposts
- How to remove SkyDrive from the Windows 8.1 Explorer
- Switching from iPhone to Android? Switch off iMessage
- Why is Google pumping more money into Firefox?
- Sky Broadband Shield review
- Samsung Galaxy S4: how to double your battery life
- Motorola Moto G review: first look
- IBM Watson meets Willy Wonka
- Google’s support policies shove users towards Chrome
- Closer to reality: photorealism in computer graphics
- Windows 8.1: Top 10 advanced features
- Securing the Internet of Things
- Internet of Things: five unlikely hacking risks
- Life behind the wall: censorship in China
- 42 best Android apps
- 3D museums that never close
- 29 best Windows 8.1 apps
- Bring an old PC up to speed
- My PC is infected: what now?
- The importance of load balancing
- Windows Phone App Studio: an easy way to create your first Windows Phone 8 app
- The end of Windows XP support: what it really means for businesses
- Don't rely on Chrome's password vault
- Using Buffer to manage your social media
- Microsoft needs its own Steve Jobs
- Forget credit cards: hackers want your Facebook account
- Can't get fast enough broadband? Here's what to do
- Leap Motion and the battle against UI stagnation
- How to build a really bad network
There are dozens of exciting prizes up for grabs on PC Pro Competitions. All our competitions are free to enter. Try your luck.ENTER NOW