home hardware prices news articles forums photos user reviews
Go Back   Tech Support Forums - TechIMO.com > PC Hardware and Tech > General Tech Discussion
Ask a Tech Support Question (free)!

Firewall myths

Reply
Get bargains at  »  Dealighted.com
 
Thread Tools Search this Thread
Currently Active Users: 1479
Discussions: 200,906, Posts: 2,378,913, Members: 246,276
Old December 31st, 2004, 03:42 PM   Digg it!   #1 (permalink)
Ultimate Member
 
DoctorReno's Avatar
 
Join Date: Mar 2003
Posts: 1,259
Firewall myths

I expect this post will generate a lot of controversy but I would like to get to the bottom of the the arguments about the value of software firewalls vs. hardware based firewalls.
I have been told by several very knowledgeable persons that running a software based firewall such as those from Zonealarm, Norton, Mcafee etc. are really unnecessary and quite useless. They advocate that the hardware firewalls in most routers are much better. Better yet, or best, is to build an old machine and use it as a dedicated firewall.

Personally, I have been using Zonealarm pro and 'thought' it was working and protecting me. I now wonder if I am just gullible and it is not doing what I believed it to be doing.

I welcome all views and information.

Thanks
__________________
If you can't say something nice... SAY IT REALLY LOUD!!
DoctorReno is offline   Reply With Quote
Old December 31st, 2004, 03:47 PM     #2 (permalink)
Did you try Google yet?
 
Siliconjunkie's Avatar
 
Join Date: Feb 2003
Location: Buckhannon, WV
Posts: 3,468
Send a message via AIM to Siliconjunkie
I don't think it is about hardware vs. software. It is about network vs application.

What I mean is that a hardware firewall (in general) only knows about addresses and ports. It has no idea WHAT is doing the talking. So, you can either allow/deny a particular type of traffic, not an application.

Firewalls like ZoneAlarm can go by application, so you can let your browser go out port 80, but that pesky spyware may get stopped. This comes at the cost of having to yes/no everything that uses the network.

They both have their own value. Personally, I don't run a software firewall. I prefer a router. But, for the more paranoid among us, ones like ZoneAlarm may appeal to them.
__________________
My computer is bigger than yours!
Siliconjunkie is offline   Reply With Quote
Old December 31st, 2004, 03:49 PM     #3 (permalink)
Retired mostly.
 
Join Date: Oct 2001
Location: Finland
Posts: 5,144
My view is that normal user can have a happy and full life with a software firewall.

Now I'm pretty certain that an external hardware firewall does excellent on incoming threat blocking. In a protected network, where there are no internal threats, it must be great.
Such network are rare imho.

A software firewall does what it's supposed to do, block illegal traffic. If it doesn't, it sure has fooled me.
muno is offline   Reply With Quote
Old December 31st, 2004, 05:25 PM     #4 (permalink)
Ultimate Member
 
Kuasimodem's Avatar
 
Join Date: Oct 2001
Location: Holmen, Wisconsin US
Posts: 2,855
Send a message via MSN to Kuasimodem Send a message via Yahoo to Kuasimodem
Or, you could be like me and run a hardware firewall (Microsoft MN-700) and ZoneAlarm. The hardware firewall stops the incoming badguys, and ZoneAlarm stops any outgoing badguys (can you say RealPlayer).
__________________
What did a tornado sound like before freight trains were invented?
Kuasimodem is offline   Reply With Quote
Old December 31st, 2004, 05:41 PM     #5 (permalink)
Ultimate Member
 
lost-and-found's Avatar
 
Join Date: Oct 2001
Location: Illinois
Posts: 2,977
Send a message via AIM to lost-and-found
here is my view: THe NAT firewall protects me perfectly from attacks on the outside. But Zone Alarm protects me from programs that are already on my computer (maybe a trojan, etc) that want to communicate with the outside network.
__________________
lost-and-found is offline   Reply With Quote
Old December 31st, 2004, 05:50 PM     #6 (permalink)
Senior Member
 
James T's Avatar
 
Join Date: Jul 2004
Location: New Zealand
Posts: 582
Quote:
Originally Posted by lost-and-found
here is my view: THe NAT firewall protects me perfectly from attacks on the outside. But Zone Alarm protects me from programs that are already on my computer (maybe a trojan, etc) that want to communicate with the outside network.

Agreed
James T is offline   Reply With Quote
Old December 31st, 2004, 06:02 PM     #7 (permalink)
still smoke free
 
RedFury's Avatar
 
Join Date: Jun 2002
Location: MinneSOta
Posts: 5,239
Blog Entries: 3
Send a message via AIM to RedFury Send a message via Yahoo to RedFury
Yup, a good firewall solution is more like plastic than gortex. You poke the holes through the plastic that you want to use, and that's it.

Gortex lets nothing in, but everthing out.

Sometimes plastics is better

now back to your regularily scheduled bad analogies.
__________________
this post contains small bits of intelligence culminating to the appearance of wisdom.

http://www.shareaproject.com/pages/p...,p,346,00.html
RedFury is offline   Reply With Quote
Old December 31st, 2004, 06:12 PM     #8 (permalink)
Did you try Google yet?
 
Siliconjunkie's Avatar
 
Join Date: Feb 2003
Location: Buckhannon, WV
Posts: 3,468
Send a message via AIM to Siliconjunkie
The big problem with things like ZA is that because it runs on the PC, it can be compromised via spy/malware.

I am sure they thought of this, but something to keep in mind.

What I would like to see is a consumer hardware firewall with the ability to write point to point rules. Where you can specify src and dst IP and such. Along with some basic traffic accounting. All the software products I have seen for Linksys are pretty much crap.
Siliconjunkie is offline   Reply With Quote
Old December 31st, 2004, 06:55 PM     #9 (permalink)
Ultimate Member
 
implexant's Avatar
 
Join Date: Jun 2002
Location: Vancouver, WA, USA
Posts: 2,696
Send a message via ICQ to implexant Send a message via AIM to implexant Send a message via MSN to implexant Send a message via Yahoo to implexant
I have an extremely security paranoid client that insists on running everything available. He has a router, ZA, and has enabled the XP SP2 firewall. I tried to tell him AVG, XP SP2 firewall, and AdAware Personal were enough to stop stuff, but he insisted on running ZA.

Well he since had to rebuild his computer because he got a TON of spyware. I prefer a hardware router/firewall solution as well. Enabling the XP SP2 firewall has proven useful as well. Generally stops network borne viruses from spreading from machine to machine on an internal network.

-Chris
__________________
http://www.implexant.com
implexant is offline   Reply With Quote
Old December 31st, 2004, 08:09 PM     #10 (permalink)
Ultimate Member
 
DoctorReno's Avatar
 
Join Date: Mar 2003
Posts: 1,259
I have a couple of old machines setting around. If I wanted to build one as a dedicated firewall how would I go about doing that?
DoctorReno is offline   Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search

Similar Threads
Thread Thread Starter Forum Replies Last Post
Okay, so you're an anti-Darwinist: Theophylact IMO Community 35 December 23rd, 2004 10:45 PM
use firewall? brianl0202 Networking and Internet 5 October 22nd, 2003 11:36 PM
Peace in the Middle East? Dmack_901 IMO Community 38 June 15th, 2003 06:06 PM
Should I try Linux? Neon Applications and Operating Systems 42 April 4th, 2002 10:01 AM


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Most Active Discussions
Is It Just Me? (2809)
Is the PSU I received dead? (10)
California Passes Anti-Flat-HDTV Le.. (39)
Install XP pro and a Vista laptop ?.. (8)
A good PSU? (10)
HIS HD5770 graphic card question (14)
Foreign voltage (6)
New Computer wont recognize XP disc (7)
Dept. of HS: NSA 'Helped' Develop V.. (12)
Print spooler problem (6)
Ideal cheap graph card for PC-Gamin.. (15)
EVGA 9800 gtx help with finding a g.. (7)
Modern Warfare 2: Who Bought It? (60)
Mysterious Boot manager (9)
Recent Discussions
EVGA 9800 gtx help with finding a goo.. (7)
Asus P4G8X Mobo (2)
Print spooler problem (6)
Need hard disk drivers (4)
windows 7 internet problem (4)
windows vista security holes (1)
What OS for a home server? (other tha.. (1)
Boot Problem? (0)
Logitech G9 laser gaming mouse $59.95.. (2)
$5 off any item with the purchase of .. (1)
Foreign voltage (6)
Ideal cheap graph card for PC-Gaming? (15)
HIS HD5770 graphic card question (14)
Install XP pro and a Vista laptop ?? (8)
Cloning old drive to new drive (6)
Amptron monitor G17FP-Black (0)
A good PSU? (10)
Is the PSU I received dead? (10)
HP Pavillion Laptop ze4220 won't turn.. (7)
Dept. of HS: NSA 'Helped' Develop Vis.. (12)
Convert 5 pin Keyboard to USB (11)
hybernate option (2)
Steam ID's, Gamertags etc... (1)
New Computer wont recognize XP disc (7)
World's largest Monopoly Game using G.. (328)


All times are GMT -4. The time now is 08:47 AM.
TechIMO Copyright 2009 All Enthusiast, Inc.



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28