Glenn, it may not look like it, but we are actually more in agreement than not. I could not agree with you more with regards to control and standardisation. This is what I have been busy doing with my clients over the last couple of years. The first step was getting similar client desktops e.g. Fujitsu Esprimo, and the same type of servers, e.g. Fujitsu Primergy. I also use as much as possible the same switches from Cisco taking the size of the network into account and whether the client requires power of ethernet etc. So yes, I agree with you 100%. Standardisation is absolutely critical. I want the same Servers, laptops, desktops, switches, routers etc etc etc. And this is actually why I want the Slackware box as this box is the most important one to standardise. Even with the broadband supplied by the council, the schools broadband connectivity equipment differs from school to school precisely because as equipment died out/phased out over the years, the council replaced them with the result that for most schools, the connection is broadly similar but not identical as some schools have a router setup through a very old switch and other schools use a white box for the router. The problem is if I buy 10 cisco whatever firewalls now, what happens in three years time, when I have new clients on board and I can't get these particular Cisco firewalls anymore. I have two choices. I can either replace all existing firewalls with something different so that everything matches and works identically or I can have slightly different equipment in each client as I get new clients on board. I intend to replace the firewall equipment every x number of years, but I cannot buy hundreds of Cisco firewalls for new clients that I have not yet got on board. My slackware box gives me complete control as the Slackware software is easy to image onto the machine. The difference in motherboards etc would not really affect anything as Linux is largely driver independent. but the same version of the OS is very important.

To your first question, the way I intend to address the confidence issue in my box, is to
a: submit it to testing using port scanners and firewall testing software to look for any weaknesses
b: By default, only certain incoming ports will be accepted. All the other ports will be set to drop all incoming connections. So I will only have potential weaknesses on an extremely small number of ports.
c: By default only certain outgoing ports will be accepted. All the other ports will be set to drop all outgoing connections. So I will only have potential weaknesses on an extremely small number of ports.
d: Slackware is a very rarely used (in comparison) OS compared to Cisco Firewalls etc. You look upon that as a weakness in terms of credentials, but I actually look upon it as a strength, as Cisco will have known weaknesses, but Slackware will be far more hack proof as most hackers have never even heard of the distro. I understand your case about not re-inventing the wheel, but it is a bit unfair to compare Slackware to a homebrew. It has been built purposely for business use. It is the most stable Linux distro out there and is absolutely brilliant with regards to control of what is installed with the OS. It is in my opinion more than fit for purpose. In addition, using the firewall on the Slackware box along with Dansguardian filtering, it means that I have one box which I can fine tune the customisation to such a level that it is a far better product than any other product at that price. While the firewall is very important, for my clients, the content filtering is actually a higher priority to them because schools are required by law to ensure that children are protected. This is the prime reason for the Slackware box.

With regards to your second point, this is another thing that is brilliant about Slackware. It primarily uses scripts. So all I have to do is copy about a dozen files that will be slightly different for each client. It will take me all of two minutes to copy the files, which means that like yourself I can setup the box in my office, in less than 30 minutes as all I will be doing is imaging the OS onto a new box, and then copy the client specific files. This is one of my biggest reasons like yourself for standardisation. This is why I have selected Slackware as it allows me to standardise the firewalling, content filtering, proxy boxes for all clients as the only real changes I have to make are to about a dozen different files. So man, we are definitely in agreement there.

But thank you for your advice in the first paragraph. I think it makes sense to use a device like the Draytek for Nat and get the Slackware box to act as a simple router, rather than doing Nat itself. I like your suggestion for setting it up. However I am not convinced that using the Draytek is a good idea because I can accomplish the same thing with the Slackare box in that I can setup Nat on the box by seting up a second network card to act as the PPPoe device. But I am still keeping it in mind. Once I get the first client setup by the end of January, I will have time to play with my options and see what gives. Essentially I need to ensure that I can get remote access to the Server, so whatever solution I come up with has to have my remote access working.

Lonkero, its not the PPPoe itself that dictates Nat per se - well at least how I understand it. But the device that supports PPPoe must support NAT otherwise the Internet would not work. Therefore the PPPoe modem/router has to support NAT, otherwise there is no way for the return traffic to get back as it cannot find the internal IP address obviously.

I have also heard good things of Billion. Draytek and Billion seem to be highly recommended in the home market. I looked at the Zyxel, and it looks like a router, not a modem and as it comes with its own firewall, it is in essence no different from the Draytek.

I better stop writing now. I am getting RSI lol.