* '''Launchpad entry''': https://launchpad.net/distros/ubuntu/+spec/improved-networking * '''Created''': <> by JohnMoser * '''Contributors''': JohnMoser * '''Packages affected''': == Summary == This spec depends on a number of sub-specs to supply improvements to networking in Ubuntu related to bandwidth usage efficiency and security. == Rationale == There are a number of tweaks that can be done to improve general security and performance of a network, including sysctl tweaks and extra daemons. == Use cases == Pertinent to the sub-specification == Scope == * [[ImprovedNetworking/DansGuardian]]: Deploy Dan's Guardian; disable by default, allow it to be enabled by user. Enabling works by telling Squid to proxy through it. * [[ImprovedNetworking/KernelSecuritySettings]]: Tweak `sysctl` settings for improved security. * [[ImprovedNetworking/NFSDefaults]]: Tweak NFS defaults for improved performance, mainly by increasing the block size from default 4K or 8K up to 32K when mounting. * [[ImprovedNetworking/SnortByDefault]]: Use Snort as an intrusion prevention system, by default. * [[ImprovedNetworking/SquidByDefault]]: Install Squid, bind it to 127.0.0.1 only, and enable it by default. == Design == == Implementation == === Code === === Data preservation and migration === == Unresolved issues == == BoF agenda and discussion == ---- CategorySpec