Re: Will A Firewall Do Me Any Good

From: Bruno Wolff III (bruno_at_cerberus.csd.uwm.edu)
Date: 12/15/04


Date: 15 Dec 2004 20:53:20 GMT

In article <5BMvd.33135$Jk5.3853@lakeread01>, Buck Turgidson wrote:
> I have a Linksys cable router. Behind it I have a Linux and a Windows
> machine. Is there any point in putting up a firewall on Linux if only port
> 22 is open on the router?

Do you trust the router?

> Specifically, I want to prevent spoof attacks, but it doesn't seem like
> Linux, being behind the firewall, not the firewall itself, would be able to
> know if the local address was coming from outside or inside.

That depends. If the attacks aren't compromising the router, you might be able
to filter based on mac address and detect spoofed packets coming from the
router that way. This will work if the "router" behaves like a "switch" for
your local network. If the router is compromised, then things become a lot
more difficult.

> Is my understanding correct? Any way to guard against spoofing with a cable
> router?

If you really don't trust the router, another option is to put to nics in
your linux box and have the router connected to one and a switch (used for
your local network) to the other and use the linux box as a firewall.



Relevant Pages

  • RE: Home Security.
    ... Subject: Home Security. ... I would suggest using linux as your router. ... Other than that, as long as you set your firewall up right, you ...
    (Security-Basics)
  • Re: Replaced NT 4 Server with Linux
    ... Maybe later when i will be more confidential with linux. ... Cisco both with the same configuration i'm doing now with your help. ... > off by a second line of defense (the Linux firewall machine you don't ... > router and keeping track of connections, running IDS's, etc - your Cisco ...
    (comp.os.linux.security)
  • Re: Linux, Windows, and cable modem
    ... > You plug system into same place you would plug router. ... I'd probably have to put it under the stairs, where there is no power, ... > linux to hub. ... > Firewall does that automagically when you setup forwarding rules. ...
    (alt.linux)
  • Re: LanMan98 problem
    ... do I really need to have Zone Alarm running on the ... >> has a firewall, use that. ... >>> Second point with regards to the router, NAT enabled, so do I need to ... > As to Linux, rather, pointless. ...
    (comp.sys.acorn.networking)
  • Re: Local Network or Internet?
    ... You shouldn't make any changes in your router, since its firewall is ... designed to keep the Internet out, not the local network. ...
    (microsoft.public.windowsxp.network_web)

Quantcast