Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other firewalls
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old January 26th, 2008, 04:03 AM
linger linger is offline
Infrequent Poster
 
Join Date: Jan 2008
Posts: 24
Default hardware firewall

Hi,

I keep hearing that using a hardware firewall is a very good security investment. But what exactly type of hardware firewall is a good amount of protection (excluding setting up a spare computer as a dedicated firewall to the outside). Is a router with NAT and DHCP what people mean by a router firewall? Also, I see more expensive routers that provide extra features like VPN. Is that really necessary?

Thanks
  #2  
Old January 26th, 2008, 04:11 AM
Eagle Creek's Avatar
Eagle Creek Eagle Creek is offline
Global Moderator
 
Join Date: Jul 2004
Location: The Netherlands
Posts: 726
Default Re: hardware firewall

Hi linger,

It depends on what you are trying to protect. If it's a company server or a web server that receives a lot of traffic, you need different equipment then when you are trying to protect your computers at home.

I'm using a Linksys Wireless ADSL-gateway with a build-in firewall and I'm happy with it.

DHCP is about providing IP addresses to your computers. NAT is about forwarding ports from the internet, to a single computer.
In my case, my NAT is disabled so all my ports are completely stealth. But if I want to, let's say, run a FTP-server, I could easily open up port 21 and make my PC accessible at port 21.

Since I know what programs I'm running on my computer, I don't use a software firewall. Although it can give extra protection, I don’t find it necessary so I can use my resources for other things.
Although most people I would recommend installing a software firewall also.
__________________
Nucia, a safe place in an unsafe world
Because the best way to kill malware, is to kill it together.


When you encounter seemingly good advice that contradicts other seemingly good advice, ignore them both.
  #3  
Old January 26th, 2008, 04:17 AM
linger linger is offline
Infrequent Poster
 
Join Date: Jan 2008
Posts: 24
Default Re: hardware firewall

Hi eagle creek,

I'm sorry, I should have been clearer. I'm just a home user. I'm running a normal router right now (that is, one that doesn't provide features like VPN I've seen on more expensive models).

Ah ok, I believe I have NAT set up on my computer. I was running a music server on my machine that I could access from work by forwarding the correct port to the music server. It seems if I disable the port forwarding, I cannot access the server from the outside, so I assume my router is blocking all requests then? So, I suppose, my question is: is running my machines behind a 'normal' router provide a good amount of additional protection for a normal home user?
  #4  
Old January 26th, 2008, 08:15 AM
YeOldeStonecat's Avatar
YeOldeStonecat YeOldeStonecat is offline
Very Frequent Poster
 
Join Date: Apr 2005
Location: Along the Shorelines somewhere in New England
Posts: 2,343
Default Re: hardware firewall

Quote:
Originally Posted by linger
So, I suppose, my question is: is running my machines behind a 'normal' router provide a good amount of additional protection for a normal home user?

Yes..by default, all home grade broadband routers and gateway appliaces (combo modem/routers) run NAT. If your computer has a private IP address (such as 192.168.1.100)....you're behind NAT. By default, all 65,000 plus ports are closed...your computer is behind a tall brick wall.
__________________
Guinness for Strength!
  #5  
Old January 26th, 2008, 08:42 AM
Eagle Creek's Avatar
Eagle Creek Eagle Creek is offline
Global Moderator
 
Join Date: Jul 2004
Location: The Netherlands
Posts: 726
Default Re: hardware firewall

Couldn't agree more.
You can check if your ports are stealth, closed or opened at this site.
(Proceed -> Test all service ports).

This will give you a nice indication .
__________________
Nucia, a safe place in an unsafe world
Because the best way to kill malware, is to kill it together.


When you encounter seemingly good advice that contradicts other seemingly good advice, ignore them both.

Last edited by Eagle Creek : January 26th, 2008 at 09:20 AM.
  #6  
Old January 26th, 2008, 10:41 AM
linger linger is offline
Infrequent Poster
 
Join Date: Jan 2008
Posts: 24
Default Re: hardware firewall

Hi,

Thanks for the replies everyone
  #7  
Old January 26th, 2008, 11:09 AM
Victek123's Avatar
Victek123 Victek123 is offline
Very Frequent Poster
 
Join Date: Nov 2007
Location: USA
Posts: 2,722
Default Re: hardware firewall

Quote:
Originally Posted by linger
Hi,

I keep hearing that using a hardware firewall is a very good security investment. But what exactly type of hardware firewall is a good amount of protection (excluding setting up a spare computer as a dedicated firewall to the outside). Is a router with NAT and DHCP what people mean by a router firewall? Also, I see more expensive routers that provide extra features like VPN. Is that really necessary?

Thanks

There are a couple of additional features which your router may support. Go into it's configuration menu with a browser and look at the firewall options. Current generation routers have SPI (stateful packet inspection) implemented. If the router supports SPI make sure it's enabled. Also, you may want to turn OFF UPnP (universal plug & play). See this article to learn about the Flash/UPnP issue.

http://www.dslreports.com/forum/r198...-strikes-again

Make sure you're not using the default password for accessing your router's configuration. The default passwords for routers are public! And does your router support wireless access? If so, make sure the wireless security is enabled (by default it's OFF). Hope this helps.
  #8  
Old January 27th, 2008, 12:45 AM
linger linger is offline
Infrequent Poster
 
Join Date: Jan 2008
Posts: 24
Default Re: hardware firewall

Victek123,

Thanks for the extra info!
  #9  
Old January 27th, 2008, 02:23 AM
cortez's Avatar
cortez cortez is offline
Frequent Poster
 
Join Date: Nov 2006
Location: Chicago
Posts: 408
Default Re: hardware firewall

Quote:
... By default, all 65,000 plus ports are closed...your computer is behind a tall brick wall.


This number (64K ports) is shocking to me. I would never have imagined there could be so many openings!!

I am now elated to have added a hardware router.

A thick brick wall seems absolutely essential given the amount of ports in existence.
  #10  
Old January 27th, 2008, 11:13 AM
Eagle Creek's Avatar
Eagle Creek Eagle Creek is offline
Global Moderator
 
Join Date: Jul 2004
Location: The Netherlands
Posts: 726
Default Re: hardware firewall

Well, yes there are. But usually only the first 1056 ports are used.
As far as I know, programmers are free to choose any port they like, as long as it isn't being used by any known applications (80: http, 21: FTP, 25: SMTP, 110: POP3, etc..).

Torrent programs are known for requesting ports in the higher range.
utorrent, for example, uses port 58595.
__________________
Nucia, a safe place in an unsafe world
Because the best way to kill malware, is to kill it together.


When you encounter seemingly good advice that contradicts other seemingly good advice, ignore them both.
 

Wilders Security Forums > Security Products > other firewalls « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 03:08 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums