Why I built my own homebrew Linux router
opensource.com
opensource.com
As to the "reliability" point: I love messing with my own networking stuff, but I've learnt the hard way that if I build my infrastructure from scratch, I'll inevitably play around with it too much and it'll break as soon as I desperately need it to just work.
I had a router like that for a couple of years running pfsense which is based on BSD but since London got a 1gbit ISP I had to switch to a normal router unless I wanted to invest like a 1000$ in hardware.
iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
iptables -A FORWARD -i eth1 -j ACCEPT
and how does it get security patches more often than Debian or FreeBSD or OpenBSD?
As an answer to the second, I checked the site and the last release was 51 weeks ago and the last beta was 3 weeks ago. Compare that to Debian archive runs a couple times a day, has a couple hundred devs, and a couple mirrors, and full security teams.
Here's a list to security related bugs that Debian has patched since the last beta of smallwall.
https://www.debian.org/security/
There's 27 debian security patches since the most recent smallwall beta, not all related to a firewall installation of course.
One has large formal teams and procedures and FAST updates.
The other ... doesn't.
If there's a problem found and released today, the first will have a patch in hours. The second will have a new beta every couple weeks, or maybe a stable release every couple years. That's a long time to wait.
One aims to do one thing and do it well (in this case, to provide a means to use an embedded PC as a secure firewall), while the other aims to provide a complete solution to make use of a vast repository of free software for many platforms.
The developer of SmallWall follows the same philosophy put in place by the developer of m0n0wall that preceeded it:
> SmallWall is a firewall, and the purpose of a firewall is to provide security. The more functionality is added, the greater the chance that a vulnerability in that additional functionality will compromise the security of the firewall.
SmallWall is barebones FreeBSD with about 10 utilities strung together to provide the functionality one would expect of a commercial-grade firewall. That's not to say that SmallWall is impenetrable, of course, but it does mean that its attack surface is a few orders of magnitude smaller than Debian's, which attempts to make possible virtually anything that can be done today with free software, on multiple architectures.
You don't have to rush to patch the latest vulnerability in a piece of software if you've made a conscious decision to avoid using that software in the first place. For instance, while people on Debian's security team scrambled to patch Shellshock, m0n0wall was unaffected because it doesn't provide shell access.
Worked very, very stable. And e machine came for free from a dumpster.
Running services were pppd, dnsmasqd, NTP, misc cron-jobs and a IPv6 tunnel.
I turned it on, assigned the network interfaces, and left it alone for about 9 months at a time. Security wasn't really the point. One device per student was allowed on the dorm network. We had three computer science students living in that room, so obviously that wouldn't fly for long.
Firstly my internet provider BT also provides premium rate TV channels via multicast, so that was fun. igmpproxy isn't in the latest couple of Ubuntu releases - i'm currently rewriting it in Golang so to spare others the pain.
Secondly, there's other things you take for granted - upnp for example, which is not great for security by default but my son would kill me if he didn't get decent XBox Live online play.
Then you've got the usual suspects - DNS, DHCP, traffic shaping per device, a DMZ for friends devices without access to my LAN, Unifi controller, the generally shitty quality of Ubuntu packages etc etc.
It's a useful exercise for learning and i'm glad I did it, but it is definitely more work than sticking a Ubuntu install on and enabling ip_forward in sysctl.
You're better off just getting a modem that speaks ethernet or using your current router in bridge mode. Consider the ethernet your demarc point. This will get you some additional galvanic isolation as well.