From: Michael Tremer
- IPFire is a server distribution with primary task as - a firewall. It also focuses on flexibility and scales very well from small to - middle-sized buisiness networks and home networks. + IPFire is a server distribution with intended to use as + a firewall. It focuses on flexibility, and scales from small to + middle sized business networks and home networks.
- Along with this very shrinked and hardened system come lots of addons that + Along with this hardened, minimalist come lots of addons that can be installed with a simple click. That's what makes IPFire different - from other distributions: It is easy to administer and has lots of power - for every challenge there might be. + from other firewall distributions: it is easy to configure for any task, + and easy to administer once it's set up.
{% end %} diff --git a/www/templates/static/about.html b/www/templates/static/about.html index 9a1f8148..ac2467be 100644 --- a/www/templates/static/about.html +++ b/www/templates/static/about.html @@ -7,7 +7,7 @@The foundation of IPFire is the high level of flexibility which lets us configure different versions of this operating system out of a single base. Beginning with a - few megabytes small firewall system it is possible to run IPFire as a file server or VPN gateway for - staff, branches or customers. This is manageable with the package manager that enhances - the system only if you really want to and makes securtity updates very easy. + small firewall system of a few megabytes, it is possible to run IPFire as a file server or + VPN gateway for staff, branches or customers. This modularity means that yor version of + IPFire runs with exactly what you require and nothing more. + All features are easily configured with the package manager, which also + makes updates very easy.
- We believe that this is the best way to provide security to a network. There is no way to give - out a static appliance because security is not a single thing to install and never touch - again. It's a kind of process paired with behaviour and restrictions. This plans could be very - different from company to company and also differ from the place IPFire is installed at. + We believe that this is the best way to provide security to a network. There is no way to + distribute a static appliance because security menas different things to different people, + and changes over time. Security is more of a process paired with behaviour and restrictions. + IPFire has been designed to be flexible enough to fit into any existing security architecture.
- Please click through the tabs and take a look at what possibilities IPFire offers for - your personal concept of network. And don't be scared. We have built-in our own to - start with... + Please click through the tabs and take a look at the possibilities IPFire offers for + your personal concept of network. + If you're still deciding what that concept is, don't worry. IPFire comes with intelligent + defaults for settings whereever possible.
{% end %} @@ -85,21 +88,21 @@ {% else %}- The matter that counts most in the development of IPFire is - of course - security. But - we don't believe that there is only one single way to achieve security. It is more important - that every administrator knows about what he is configuring and that he is teached about what - is right in his special environment. + The primary objective in the development of IPFire is - of course - security. But it doesn't + mean there is only one way to achieve security. Rather, it is more important for every + administrator to understand their environemnt and what security means in that context.
- IPFire is the base of security in the network. It has the power to separate the network into - smaller parts rated by their security level. That's what makes it more easy to create a custom - policy for every part. See the firewall tab to learn more about that. + IPFire is the base of security for a local network. It has the power to segment the network based + on their required security level. This makes it easy to create custom policies for each segment. + See the firewall tab for more information.
- Another very important thing the developers focus on is the fast and reliable distribution - of security updates of the system or its components like the Linux kernel, libraries, etc. - As IPFire is directly connected to the internet it is a primary target for hackers and bots - we have to fight against. + Part of this focus on security involves the fast and reliable distribution of security updates + of the system and its components. Updates are digitally signed and encrypted, and can be + automatically installed by the Pakfire, the package manager. Since IPFire is directly + connected to the Internet it is a primary target for hackers and bots. Pakfire helps + administrators feel certain they are running the latest security updates and bug fixes.
{% end %} @@ -124,19 +127,18 @@- From the technical point of view, IPFire is a very shrinked and hardened firewall system - which comes with an integrated package manager that is called Pakfire. - With only a single click you can extend your system to a server that provides services from different - categories. + From a technical point of view, IPFire is a minimalistic, hardened firewall system + which comes with an integrated package manager called Pakfire. With a single click you + can enhance the base system by providing network services.
- The most interesting addons: + Some interesting addons:
- IPFire comes with a SPI (stateful inspection) firewall which is built on top of the - Linux netfilter. + IPFire uses a firewall using Stateful Packet Inspection (SPI) which is built on top of + netfilter, the Linux packet filtering framework.
- With the installation of IPFire, the network gets seperated into different parts that - represent a special kind of computers with their own level of security: + With the installation of IPFire, the network gets separated into different segments which + represent a group of computers which share a common security level:
- So there is a best place for every machine in the network. All the segments can be activated seperately
- (except green and red are always required).
-
- On top of all of that, there is an outgoing firewall for filtering the egress direction.
+ This scheme means there is a perfect place for each machine in the network. The various
+ segments may be enabled separately depending on requirements. Additionally, the firewall
+ can also control outbound Internet access from any segment. This gives the administrator
+ ultimate control over how their network can be used.
- IPFire can be enhanced to a VPN (virtual private network) gateway that connects places and - persons to the local network. This could either be staff, friends and people you want to share - data with in a secure way but also could be a branch office, important customer or an other - company you are operating with. -
-- To be able to dock on different technologies IPFire offers these implementations: + IPFire may be enhanced to include a virtual private network (VPN) gateway which connects + remote people and places to the local network using an encrypted link. This could be staff, + friends, or anyone you'd like to share data with in a secure way. Businesses use VPNs to + connect branch offices, datacenters, corporate partners, and to provide traveling staff + with a portal into the corporate network.
-- Those implementations let IPFire connect to routers or VPN gateways by: + IPFire uses both the IPSEC and OpenVPN protocols, affording the maximum in flexibility + when configuring your VPN. These implementations allow IPFire connect to VPN endpoint + devices by: Cisco, Juniper, Checkpoint, - other Linux-based implementations and many more... + NetGear, or any Linux based implementation.
{% end %}@@ -328,27 +325,29 @@
{% else %}- Based on a recent version of the Linux kernel 2.6 series, IPFire supports latest hardware - like 10G network cards and wireless hardware out of the box. + Based on a recent version of the Linux kernel 2.6 series, IPFire supports the latest hardware + like 10Gbit network cards and wireless hardware out of the box.
- It is at least a Intel Pentium I compatible CPU (i586) required and we recommend - approx. 128 MB RAM (or more) and 1GB disk space. + Requirements are minimal: an Intel Pentium I compatible CPU (i586), 128 MB RAM, + and 1GB disk space.
- For routing, there are at least 2 network interfaces required. - Alternatively, a 3G-modem can be used. + For routing, at least 2 network interfaces are required. + Alternatively, a 3G modem may be used.
- Developers are concerned about keeping the system running on many variations as - possible what makes IPFire run on cheap hardware as well as running on high - performance servers. + The IPFire Developers are concerned with the ability to run IPFire on systems running as many + variations as possible. This is what helps IPFire run on cheap hardware as well as high + performance servers.
{% end %}- {{ _("Hardware section on the wiki") }} + {{ _("Fireinfo") }} + • + {{ _("Hardware section on the wiki") }} • - {{ _("Hardware compatibility list") }} ({{ _("networking") }}) + {{ _("Hardware compatibility list") }} ({{ _("networking") }})
IPFire is licensed under the terms of the GNU General - Public License in version 3. So it is free software. + Public License in version 3, so it is free software.
- There is the opportunity to make a donation to the - community which is a very important thing for the success of the project. + The success of the project depends upon donations + to the community.
Free software allows (under the terms of the GPLv3):