Networking Forums

Networking Forums > Computer Networking > Broadband > Question about Firewalls

Reply
Thread Tools Display Modes

Question about Firewalls

 
 
Travec The Dacian
Guest
Posts: n/a

 
      10-27-2006, 10:36 AM
Sorry if this is a little OT. I run a home wireless network which
accesses the internet via a Linksys broadband router+modem. The
router has a built-in firewall (but it looks pretty basic to my
uneducated eye). Do I REALLY need a separate firewall on every PC on
my network or is the firewall in the router sufficient on its own,
bearing in mind it's just a home network.

TIA

Travec
 
Reply With Quote
 
 
 
 
Martin Underwood
Guest
Posts: n/a

 
      10-27-2006, 10:47 AM
Travec The Dacian wrote in
(E-Mail Removed):

> Sorry if this is a little OT. I run a home wireless network which
> accesses the internet via a Linksys broadband router+modem. The
> router has a built-in firewall (but it looks pretty basic to my
> uneducated eye). Do I REALLY need a separate firewall on every PC on
> my network or is the firewall in the router sufficient on its own,
> bearing in mind it's just a home network.


My understanding is that the NAT aspect of a router acts as a pretty good
firewall to protect you against incoming threats because it will not pass
any unsolicited traffic, only traffic that is in response to a request (eg
for a web page or to read a POP mailbox) from a PC on the private network.

What it won't do (and nor will the Windows XP firewall) is to protect you
against programs on your PC trying to access the Internet. To guard against
that you need a firewall such as Norton Internet Security or Zone Alarm.
This will ask for your permission for each program on the PC that wants to
access the internet, the first time that program attempts to do so; having
trained the firewall to accept or to block a given program, the same
behaviour will be used in future, so you won't be asked each time you run
IE, for example.


 
Reply With Quote
 
Colin Wilson
Guest
Posts: n/a

 
      10-27-2006, 12:39 PM
> Do I REALLY need a separate firewall on every PC on my network

I would - you have no way of stopping outbound traffic otherwise.

Do you have anything else in place to increase security / lock down the
machines ? (i.e. alternative browsers, spyware detection, anti-virus) -
if not, it might be worth kitting them all out the same...
 
Reply With Quote
 
Roger Mills
Guest
Posts: n/a

 
      10-27-2006, 12:46 PM
In an earlier contribution to this discussion,
Martin Underwood <a@b> wrote:

> Travec The Dacian wrote in
> (E-Mail Removed):
>
>> Sorry if this is a little OT. I run a home wireless network which
>> accesses the internet via a Linksys broadband router+modem. The
>> router has a built-in firewall (but it looks pretty basic to my
>> uneducated eye). Do I REALLY need a separate firewall on every PC on
>> my network or is the firewall in the router sufficient on its own,
>> bearing in mind it's just a home network.

>
> My understanding is that the NAT aspect of a router acts as a pretty
> good firewall to protect you against incoming threats because it will
> not pass any unsolicited traffic, only traffic that is in response to
> a request (eg for a web page or to read a POP mailbox) from a PC on
> the private network.
> What it won't do (and nor will the Windows XP firewall) is to protect
> you against programs on your PC trying to access the Internet. To
> guard against that you need a firewall such as Norton Internet
> Security or Zone Alarm. This will ask for your permission for each
> program on the PC that wants to access the internet, the first time
> that program attempts to do so; having trained the firewall to accept
> or to block a given program, the same behaviour will be used in
> future, so you won't be asked each time you run IE, for example.


I would concur with that. If you don't want to spend any money, I would
recommend putting the free version of ZoneAlarm on each PC. It's perfectly
adequate for most purposes unless you're doing anything fancy with your PC.
It's still available, but not as easy to find as it used to be because Zone
Labs - for obvious commercial reasons - would rather *sell* you the PRO
version than give you the free one. So read the small print to make sure you
get the free one - and not a time-limited free trial of the PRO version.

The firmware firewall in the router plus a software firewall in each PC
should give pretty good protection against internet-borne nasties - assuming
that you're also running anti-virus software. But they provide no protection
against people gate-crashing your wireless LAN - so make sure you're using
the highest level of encryption which that supports, preferably coupled with
MAC address filtering, and changing the SSID to something other than the
default, and not broadcasting it.
--
Cheers,
Roger
______
Email address maintained for newsgroup use only, and not regularly
monitored.. Messages sent to it may not be read for several weeks.
PLEASE REPLY TO NEWSGROUP!


 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
question on static IPs and firewalls biff Windows Networking 3 08-07-2009 08:18 PM
Stateful firewalls and dynamic routing question. abstractclass Linux Networking 11 10-23-2006 06:17 PM
firewalls Me Broadband 15 11-16-2004 07:59 AM
ICS & Firewalls Trevor Dennis Broadband 11 09-19-2003 07:44 PM
firewalls 101 - what goes where Gary N. Linux Networking 1 09-08-2003 10:56 AM



1 2 3 4 5 6 7 8 9 10 11