First of all, great project! I've often thought how
useful it would be to have a Linux-style transparent
bridging firewall and (even more importantly)
bandwidth control.
However, I think this could be even more valuable if
it could be used on a gateway connection. Would it be
possible to add dual-NIC functionality so Sieve can be
used on a gateway? In other words, bind two VM
adapters to two physical NICs and place them in-line
with the gateway connection. Then you'd have powerful
firewall and bandwidth control over the entire WAN
connection. This would become even more powerful if
Snort was implemented.
Of course, once we have a good solution, you'll
definitely have to port it over to a hardware device
(think $100 box that plugs inline into the WAN
connection). I can name quite a few interested
customers.....this would be a great tool for improving
security and managing bandwidth at remote offices,
congested WANs, or even home networks.
Logged In: YES
user_id=521639
We've been thinking along the same lines, especially
regarding an inline firewall.
We're trying to figure out what the next release is going to
look like, and it's looking like the VM will only one of
several options for output. Others would include a
straightforward bootable ISO, and whatever is required for a
smaller platform.
If someone were to donate some development hardware to do a
build on, we could get it running on it... (hint, hint)
Mike