Re: Router vs. desktop firewall

From: Mark Adams (madams9_at_juno.dotcom)
Date: 12/31/03


Date: Wed, 31 Dec 2003 17:16:44 GMT

Thomas Hertel wrote:
> Mark Adams <madams9@juno.dotcom> schrieb:
>
> [snip]
>
> However, you should not block WAN traffic, but reject it. As you
> mentioned yourself, Shields Up (and thus any other scanner and any
> potential attacker) sees your "stealthed" ports anyway. If you do not
> have any port open, you are fine. The word "stealth" is not even worth
> the air it takes to carry it from me to you.
>
> Regards
> Thomas

My understanding is kind of the opposite. If I reject packets, the
sender knows the port is there, but rejecting: packet comes to my
router, router replies, "Nobody here but us chickens!" Sender knows,
"there's chickens in there."

If I "stealth" the port, a packet comes in, router ignores it and does
not reply at all. The sender sees nothing and therefore does not know
that the port exists.

Or am I misunderstanding this?

Thanks.

Mark



Relevant Pages

  • Re: Netopia R910 and servers
    ... "Thomas Hertel" wrote in message ... >>serve out my blog. ... My ISP is my cable provider, and they started blocking web servers when ... I totally agree with them blocking port 80, ...
    (comp.security.firewalls)
  • Re: Remote admin.....is that really safe?
    ... Thomas Hertel wrote: ... he's talking about remote admin of the router... ... What I usually do, is ssh into the box *behind* the router, (said router ... No remote admin on the Wan side at all. ...
    (comp.security.firewalls)