Re: Why do I need a software firewall?

From: xpyttl (xpyttl_NOSPAM_at_earthling.net)
Date: 09/30/05


Date: Fri, 30 Sep 2005 08:47:51 -0400


"Volker Birk" <bumens@dingens.org> wrote in message
news:433ce341@news.uni-ulm.de...

> *sigh* - the "nickel answer" is totally wrong. Outgoing TCP sockets can be
> filtered by every of the filtering solutions (if they're implementing this

What the software firewall brings to the table is the ability to limit
outgoing connects to specific PROGRAMS. This is not something the hardware
firewall can provide. Realistically, the hardware firewall only forces me
to open some ports, unless I'm never going to connect to the net. Most
worms take advantage of this and really like to use port 80. What the
software firewall allows me to do is close port 80 except for Firefox, for
example. Sure, I could block outgoing port 80 at the hardware firewall, but
then I'd have to give up browsing the web.

I did not mean to imply that the software firewall should be used instead of
a hardware firewall. The hardware firewall is a LOT more important than the
software firewall. But the software firewall adds some granularity to the
control the hardware firewall provides.

Sadly, probably 99% of the Internet connected PCs that have any protection
at all only have software protection, which as you point out, it totally
inadequate.

..



Relevant Pages