Re: Which home user router has a decent firewall inside it?



John Adams <no@xxxxxxxxxxxxx> writes:

Gerald Vogt wrote:

Because that is not what the firewall of an average consumer brand
router does. Not for your LAN. The NAT translation on the router will
discard "unsolicited" packets. NAT will inspect any packets if at all.
You'll see the difference in the moment you turn off NAT (i.e. you
use
public IP addresses in your LAN) and keep the firewall active. In that
moment nothing will be filtered between the internet and your LAN
simply because by default the firewall on the router protects the
router itself but not your LAN.
Gerald


OK, and that is why you should run hardware router firewall and
software firewall too? I'm not on a LAN anyway. This is just for home
use. I share files between computers by using a USB thumbdrive.

The traditional answer to that is that a "software firewall"
generally has egress filtering and can alert you to specific programs
trying to get out to the internet, whereas a hardware device can't
give you such clues.

If the primary concern is blocking unsolicited traffic from the
internet, a sane SPI home gateway device should do fine.

The hardware device is generally a more robust solution because the
"personal firewall" software runs on top of windows... and we know
that windows is fairly complex and no infallable to say the least.

Just like network based and host based intrusion detection products
offer complementary protection, so do hardware and software "firewall"
solutions.

--
Todd H.
http://www.toddh.net/
.



Relevant Pages

  • Re: New modem and iptables...
    ... The router performs firewall and NAT functions ... If you want to persuade me it's a modem, ... it's a router and _it_ has your public Internet address. ... It also does NAT (otherwise you couldn't have a private IP address on ...
    (Fedora)
  • Re: Would a firewall prevent Sasser worm?
    ... >> the same level of protection that I would have with any NAT router? ... >There are a variety of known attacks which can crash routers, ... >Firewall capability allows you to modify the NAT behaviour to allow selected ...
    (comp.security.misc)
  • Re: Would a firewall prevent Sasser worm?
    ... >> the same level of protection that I would have with any NAT router? ... >There are a variety of known attacks which can crash routers, ... >Firewall capability allows you to modify the NAT behaviour to allow selected ...
    (comp.security.firewalls)
  • Re: Would a firewall prevent Sasser worm?
    ... >> the same level of protection that I would have with any NAT router? ... >There are a variety of known attacks which can crash routers, ... >Firewall capability allows you to modify the NAT behaviour to allow selected ...
    (alt.computer.security)
  • Re: IP Addressing
    ... Address of the ISA server? ... firewall and router). ... On the firewall create a static NAT entry as I wrote ...
    (comp.dcom.sys.cisco)