Re: Is Software Firewall Necessary with a H/W already running?

From: Andrew Rossmann (andysnewsreply_at_no_junk.comcast.net)
Date: 07/30/04


Date: Fri, 30 Jul 2004 16:24:33 -0500


[This followup was posted to comp.security.firewalls and a copy was sent
to the cited author.]

In article <CdyOc.182482$tH1.8031261@twister.southeast.rr.com>,
rsmith.remove@triad.rr.remove.com says...
> I finally purchased a hardware firewall (Netgear FVS318). Alot of
> helpful people in the group suggested I go hardware to free some
> resources and cycles. However, I have seen some people that use BOTH
> H/W and S/W firewall. I scanned my system with ShieldsUp! and found
> everything is stealth. My question is:
>
> Do I still need a software firewall with this hardware one installed?

  It's still a good idea. In particular, most software firewalls also
monitor outgoing data on a PER PROGRAM basis. You can control excactly
which programs have access and prevent anything being sent, even if it's a
common port like 80.

  Basically, unless you have a VERY fast connection, and a VERY slow
computer, the speed loss shouldn't be a big deal, if it's even detectable.
You could always help things a bit by setting the software firewall to
allow all incoming, if you believe the hardware firewall will fully
protect you.

  Just remember that just blocking data ports alone doesn't cut it these
days. With spyware, adware, trojans, etc.. you need help on actual program
control.

-- 
If there is a no_junk in my address, please REMOVE it before replying!
All junk mail senders will be prosecuted to the fullest extent of the 
law!!
http://home.att.net/~andyross


Relevant Pages

  • Re: Is Software Firewall Necessary with a H/W already running?
    ... >>Do I still need a software firewall with this hardware one installed? ... You can control excactly ... > Just remember that just blocking data ports alone doesn't cut it these ...
    (comp.security.firewalls)
  • Re: Software Firewalls are "Snake Oil" !
    ... >than any 'software firewall' ". ... Hardware boxes are better because they ... You are running amok but SamSpade is right. ...
    (comp.security.firewalls)
  • Re: Kerio and XP
    ... replaced the TCP protocol with one of it's own. ... Now if something so simple can bypass a software firewall it takes ... little imagination to guess what Mickeysleaze can do at the hardware ...
    (comp.security.firewalls)
  • Re: Bad characters in Recent File list
    ... > I have the latest Norton virus protection/Internate security as ... > a hardware and a software firewall and several programs against ... spyware and I have a hardware firewall (it came with my ...
    (microsoft.public.vb.general.discussion)