Firewall BEFORE the modem.

Discussion in 'other firewalls' started by invaderz, Dec 15, 2013.

Thread Status:
Not open for further replies.
  1. invaderz

    invaderz Registered Member

    Joined:
    Dec 3, 2013
    Posts:
    22
    Would it be possible to purchase a firewall that comes before the modem? For example a fire wall that only accepts a coaxial cable or fiber optics.

    Not sure how it would work but im thinking it would be able to block packets that arent coming from the isp or something. This way the MODEM is only interacting with the ISP.

    There is a serious problem going around not many people know about and that is MODEM hardware hacking.

    If anyone knows a great solution to the modem protection problem please let me know I really want to keep my modem safe.
     
  2. invaderz

    invaderz Registered Member

    Joined:
    Dec 3, 2013
    Posts:
    22
    If no fire wall exists that you can use as defence for your modem is there a modem that has a built in firewall to fight attacks against the network?
     
  3. noone_particular

    noone_particular Registered Member

    Joined:
    Aug 8, 2008
    Posts:
    3,798
    A lot of modems do include a firewall. All of the ISP supplied modems I've had also have a firewall in them. Unfortunately, all of these modems also have an undocumented open port that can't be closed by configuration. I'm not aware of any firewall that you can install ahead of a modem. If there was, I'm not sure if such a device would be that useful. There are modems available as PCI cards. Smoothwall used to have a DSL modem available through their site that could be made part of a hardware firewall. I've never tried it.
     
  4. invaderz

    invaderz Registered Member

    Joined:
    Dec 3, 2013
    Posts:
    22
    Thanks for the knowledgeable reply. I noticed a Cisco modem card today when i was looking for the answer. Do you think most ISP can let me use one?
     
  5. noone_particular

    noone_particular Registered Member

    Joined:
    Aug 8, 2008
    Posts:
    3,798
    I don't know if or how many have policies that require you to use their equipment. A residential service provider might prohibit you running a server and would be hesitant to let you use equipment that would make that possible. For the most part, you just need to duplicate the settings used by their modem. The hard part might be getting access to those settings. If you duplicate their settings and don't use it to defeat restrictions on how you use the service, it's unlikely that most ISPs would notice the change.
     
  6. m0unds

    m0unds Guest

    a modem integrated into a discrete firewall device will still operate in front of the packet filtering functionality built into said firewall. as far as compatibility, contact your cableco and ask them for a hardware compatibility list. most cablecos have a list of tested, compatible CPEs that can be used with their systems.
     
  7. tomazyk

    tomazyk Guest

    You should ask your ISP. You will need correct settings for modem and will probably have to inform ISP of new device, telling them new device's MAC address, so they can configure things on their site.
     
  8. Aryeh Goretsky

    Aryeh Goretsky Security Expert

    Joined:
    Apr 4, 2006
    Posts:
    54
    Location:
    United States
    Hello,

    There are no firewalls which go in front of the coax (aka WAN or HFC) connection of cable modems. For one thing, these might interfere with the ability of the cable provider to manage the modem.

    Your best bet, as far as any security goes, is to probably invest in a DOCSIS 3.0 cable modem (assuming your cable provider support this latest version of the standard and allows you to provide your own modem), which they then become responsible for provisioning and managing.

    Even when the cable modem is provided by you, the cable company is responsible for its settings and connectivity, and in the event of a hacking incident, they would be responsible, not you, for remediating it. Of course, you would probably still want to file a report with both local law enforcement and your state's public utilities commission (or its equivalent outside the United States) if you were the victim of a cable modem-based hack.

    Regards,

    Aryeh Goretsky
     
Loading...
Thread Status:
Not open for further replies.