Re: Firewall yes, but where?

From: MyndPhlyp (nobody_at_homeright.now)
Date: 02/20/05


Date: Sun, 20 Feb 2005 14:22:06 GMT


"Klaus Haber" <Klaus.Haber@bingo-ev.de> wrote in message
news:1iz765qlbmaqe.vc5phlerzdnb.dlg@40tude.net...
> Hello,
>
> I have an understanding problem. There are different meanings concerning
to
> use firewalls or not. But generell I heard, that a firewall in a _router_
> in connection with a DSL-PC is better than a firewall integrated in the
> same PC, connected to the net by a _modem_. (Firewall means personal
> firewall).
> My understandig ist, that there is no differenz between this both
> configurations. If the router firewall leaks, the attack will reach the
PC.
> The same happens, if the PC-firewall will leak. I see only one advantage
in
> a router-firewall, if you have a local net with different PCs. In this
case
> you need only one firewall for all connected PCs.

Both solutions have their benefits and drawbacks as you have observed.
Generally speaking ...

The firewall appliance will filter and route port and protocol traffic but
doesn't care about application-level stuff (e.g., it doesn't know if the
port 80 traffic originated from Netscape Navigator or Kazza). The up side is
that the entire LAN receives its protection from a single point. The down
side is that trojans and worms riding on port 80 (and similar scenarios)
cannot be blocked.

The personal firewall approach will also filter port and protocol traffic as
well as block or allow traffic at the application level but won't do port
routing. (Port routing is of importance only if you are offering services to
the WAN.) The up side is that the user can control which applications access
the WAN and the LAN. The down side is that only a single machine is
protected.

IMO (naturally), leaks should never exist except in salads, soups (properly
spelled "leek"), sieves, or in the general vicinity of a water closet, tree,
or other isolated area. If a firewall leaks, it isn't much of a firewall. If
your concern is along those lines, it would be prudent to consider multiple
layers of firewalls - both appliance and personal firewall solutions.



Relevant Pages

  • Re: AS4.2/WM5/OUTLOOK2K3 suddenly not syncing, please help
    ... there is a connection EXIST between the device because I ... connection on port 26675 but on the PPC the port number keeps ... Outlook, countless times of reinstalling Activesync, removing Windows ... Firewall set to NO). ...
    (microsoft.public.pocketpc.activesync)
  • RE: FTP Window of opportunity?
    ... target on the line when in reality it was just a firewall lying to them. ... The connection connects and then immediately ... Subject: FTP Window of opportunity? ... the FTP port shows up. ...
    (Pen-Test)
  • Re: keeping ports open
    ... If a port is open, it means that 1) a software or service is running on your ... and 2) you're not using a firewall or your firewall isn't ... Use firewall software and hardware and antivirus software that is ... Follow the instructions for hardening Windows and IIS at ...
    (microsoft.public.security)
  • Re: How to Maintain an IIS Server?
    ... > server running on a Windows 2000 server. ... before a firewall and antivirus have been installed]. ... open ports; however, this will not identify which program is using the port. ...
    (microsoft.public.inetserver.iis.security)
  • Re: CEICW fails at firewall config
    ... ISA Server prevents connection to a remote desktop when you connect through ... Remote Web Workplace on a Windows Small Business Server 2003-based computer ... Acceleration Server as a firewall. ... connection uses TCP port 4125. ...
    (microsoft.public.windows.server.sbs)

Quantcast