View Full Version : Untrusted computers sharing router
NoHolyGrail
August 15th, 2007, 07:27 PM
Beginning with the assumption that a software firewall is not necessary when behind an NAT router, does a software firewall become necessary when you do not trust the other computers connecting with that router?
For example, I'm going to be sharing a wireless internet connection with housemates. I trust them not be doing anything malicious, but I don't trust their computers to be clean from infections at all times. What risks, if any, does this create for my computer?
19monty64
August 15th, 2007, 09:24 PM
A software firewall is used for outbound protection when using a router, and that router allows your network in. So if they get infected there is notthing to protect you. Get a s/w-f/w!!!
innerpeace
August 15th, 2007, 10:55 PM
monty is correct, The router only protects things from getting in at the gateway to the internet. It will not protect you from the other computers behind it. If one computer gets infected, it could very well infect all others on the network.
From what I understand, even windows firewall can protect you against all inbound attempts. If you have Vista firewall, it can protect both inbound and outbound connections on your machine. Outbound protection is useful if you do happen to get infected to stop the malware from calling home or sending out your personal information/passwords/bank accounts etc. There are other nasty things malware can do with an outbound connection.
beads
August 17th, 2007, 05:44 PM
You could look into investing in a MS ISA type proxy as well for additional protection. You'd need a cheap or older machine running MS Web server or Standard, etc. Other options would include numerous forms of Linux, etc.
From there you could look into running Trend Micro IWSS for about $200 (USD) a year and have no worries. That sounds a bit draconian but still for a handful of dollars and some old hardware you could probably do all of this on the cheap with some homework and old pieces and parts.
NoHolyGrail
August 20th, 2007, 08:04 PM
{QUOTE-> You could look into investing in a MS ISA type proxy as well for additional protection. You'd need a cheap or older machine running MS Web server or Standard, etc. Other options would include numerous forms of Linux, etc. <-QUOTE}
Along those lines of configuring a spare computer as a hardware firewall, would it be possible to connect a second router between my computer and the main router?
wat0114
August 20th, 2007, 11:00 PM
It does not have to be complicated or expensive. Just disable Windows file sharing and use the built-in firewall whether it be XP or Vista.
vBulletin® Copyright ©2000-2009, Jelsoft Enterprises Ltd.