Zorp is a new generation firewall. It is essentially a transparent proxy firewall, with strict protocol analyzing proxies, a modular architecture, and fine-grained control over the mediated traffic. Configuration decisions are scriptable with the Python based configuration language.
Zorp has been successfully deployed in demanding environments like the protection of high traffic web sites, or the protection of large intranets. Since the protocol analysis is strict and many of the common exploits violate the application protocol they are injected into, a large percentage of the attacks do not cross a Zorp based firewall even if the given service is permitted.
In a labor environment we could fully saturate a 100MBit ethernet link, and use up to about 600MBit of the bandwidth of an 1000MBit ethernet link. In real life situations we saturated a 10MBit internet link with 500 parallel sessions.
|
|
|
| Architecture | Package Size | Installed Size | Files |
|---|---|---|---|
| alpha | 97.6 kB | 516 kB | [list of files] |
| amd64 | 97.3 kB | 512 kB | [list of files] |
| armel | 96.0 kB | 492 kB | [list of files] |
| hppa | 99.2 kB | 500 kB | [list of files] |
| i386 | 96.9 kB | 496 kB | [list of files] |
| ia64 | 105.6 kB | 548 kB | [list of files] |
| m68k (unofficial port) | 95.5 kB | 492 kB | [list of files] |
| mips | 96.2 kB | 508 kB | [list of files] |
| mipsel | 97.9 kB | 508 kB | [list of files] |
| powerpc | 101.1 kB | 508 kB | [list of files] |
| s390 | 100.0 kB | 504 kB | [list of files] |
| sparc | 97.1 kB | 496 kB | [list of files] |