IpCop firewall problems

Asha'man X

Expert Member
Joined
Aug 31, 2006
Messages
1,401
Reaction score
23
Location
Cape Town
I hope someone can give me some solutions or ideas concerning this little problem I had recently with IpCop.

I worked at my old high school last week, tuning and tweaking and other things, and that included some settings on IpCop to make it more efficient. There was also a strange problem where ping times to the box would go crazy, and internet access would get cut off. There was no real reason why it would do this, it just happened randomly.

The green interface is a Realtek 8139, the red one was a CNET 100 something, but now changed back to onboard VIA Rhine. The red interface runs to an Iburst UTD.

I tried replacing the cards, and using setup from the console menu, tried to scan for new cards. That's when the problems started. IpCop either didn't pick the cards up, assigned them in the wrong order, only picked one up, same sort of troubles. Even deleting the Networking file where it keeps it's setting didn't help when it ame time to rescan. Still picked up the same cards even after I had replaced them with others.

This happened on 1.4.10, and later also on 1.4.18 after a fresh install. Suffice to say it was very frustrating. I don't have much experience with IpCop or Linux based firewalls, but once IpCop is running, it works well without any issues.

Is there any way to fix this problem from coming up again, or should I recommend that they switch to Smoothwall or some other free firewall? It is alive and working now, but I don't want them calling me everytime there is an issue. I just want the thing to run quitely and behave.
 
VIA rings *big* warning bells. According to many sources, VIA cards do not behave well on the PCI bus.

I would try another make of NIC (Like Realtek) and see if you get similar problems.
 
@ AK65

Thanks for the tip. I've never really been a VIA fan anyway, but in this case it seems to have behaved itself on that IpCop box. If anything goes crazy, I'll hear about it next week when that school reopens.

Taking the CNET card out, and using the VIA onboard and the Realtek seems to work better than with the CNET in.

As long as it works now, I'm happy. Just wish I knew more about these small firewalls. I need to check Smoothwall out maybe.
 
Yr welcome ;)

I have only mucked about with IPCOP - never deployed it seriously because I use GPRS on cardbus and it doesn't do that......

I have read on numerous sites that VIA hangs the PCI bus and makes it difficult to run real-time applications - so I avoid anything VIA like the plague......
 
Ashaman - I can recommend 3Com NIC's - cheap NIC cards have small buffers and tend to bugger up transfers on the network in general.

I used a VIA mobo once, worked quite well, but the only problem I've had were always the cheap NIC's which tend to pack up, or develop some spurious and wonky problem.

A good and proper NIC might be expensive, but they do last longer than cheapshot NIC's.

Did you also tried Smoothwall to see if the issue persists?
 
I've never encountered problems with VIA chipsets, but Lib's advice and use 3com chipset based cards. They're a tad more expensive but worth it.
 
Thanks everyone for the tips and advice.

I haven't been back to my old high school now for 2 weeks, they still closed for their holidays, the lucky people.

If there's any problems with IpCop from Monday on, I'll hear about it. I can only hope that the upgraded version and the changed cards will continue to work steadily. The next time I go there will be to help configure their second server to the join domain and integrate everything.

Unfortunately I didn't have my Smoothwall copy on me at the time or I may have tried it out. Maybe that 2.6 kernel series will do the trick. If the problems go on, I'll be tempted to install it and give it a shot. The school won't have any 3COM cards I think, but if need be I can always suggest they purchase some.

I am quite impressed though by IpCop. With some mods thrown on, it actually makes a pretty decent security solution. :)
 
replace setup with MikroTik router... Easy and simple to use
I really do recommend these routers, I've dumped all my IPCOP boxes a few years ago.

Sometimes it's not worth it to 'sukkel', especially with old hardware
 
Top
Sign up to the MyBroadband newsletter
X