freedomofpress / securedrop

GitHub repository for the SecureDrop whistleblower platform. Do not submit tips here!
https://securedrop.org/
Other
3.62k stars 686 forks source link

Evaluate NetGate SG-4100 #6374

Closed zenmonkeykstop closed 2 years ago

zenmonkeykstop commented 2 years ago

Description

The Netgate SG-4100 looks to be the replacement for the currently-recommended pfSense firewall (SG-3100). It's a little overspecced but should be a decent SD hardware firewall.

We should set up an instance with it and confirm the current setup instructions - it will probably use a variation on the 4-NIC setup as it has enough NICs to support it (as opposed to to the 3-NIC setup for the SG-3100).

cfm commented 2 years ago

I have some notes on the four-NIC setup I did for my SG-6100 that I'll draft in securedrop-docs in case they're adaptable for the SG-4100 as well.

zenmonkeykstop commented 2 years ago

SG-4100 has been evaluated, works well. Setup instructions have been added and a PR adding it to reccomendations is pending: https://github.com/freedomofpress/securedrop-docs/pull/356

This can be closed.