
6.3 Selecting an operating system 115
Chapter 6
inefficient and burdensome. An overlay network is, for most of the
population, unfeasible.
This brings the focus back again to hiding. A clever firewall hides
things. It hides itself, hides its own ports, and effectively renders the
internal network completely invisible. This can be accomplished by
carefully selecting the firewall based on its capabilities, by installing
it in the best location, and through the nature and type of operating
system (OS). Not all OSs are created equal, but not necessarily for
the reasons many people think.
6.3 Selecting an operating system
Whether building a firewall from scratch, ...