Re: ADSL connection dropping randomly

From: Richard E. Silverman (res_at_qoxp.net)
Date: 04/27/05


Date: 27 Apr 2005 09:23:46 -0400


> Richard, I'll have to back up other posters that say a router is safer and
> more secure than using a personal firewall...

As I already said in a followup, I agree with the idea that a separate,
special-purpose device may be less likely for a naive users to
inadvertently screw up. I disagree with the OP's original statement,
which was that "hardware firewalls" are somehow *inherently* better -- as
if the fact that it doesn't *look* like a computer makes it some other,
and superior, species of security device. That is nonsense.

> Routers are appliances, not computers,

This is simply false. They are appliances, *and* they are computers. A
Linksys router is no more and no less than Linux box with multiple network
interfaces and a web GUI for configuring certain networking features.
Period. As I said, I agree that its form and separation from a user's
workstation can make certain mistakes less likely -- but in competent
hands, a "regular" Unix box (bigger, noisier, with a disk drive, etc.) is
equally effective.

> I don't know of ANY router (NAT) users that have been compromised because
> of using a router, but I know many that have been compromised because they
> were using a Personal Firewall Application and thought it completely
> protected them.

This is a specious comparison. A more meaningful one would be with people
compromised because they thought their router "completely protected them."

-- 
  Richard Silverman
  res@qoxp.net


Relevant Pages

  • Re: Separating networks
    ... > what is the best way to separate 2 company's network. ... > They share same cabling and subnet. ... You could use a router or firewall. ...
    (microsoft.public.security)
  • Re: WINS problem Help!!!
    ... wireless in their router set up with two separate IP addresses. ... A VPN Router is really just a Firewall or Router that also has VPN ...
    (microsoft.public.windows.server.networking)
  • Re: [fw-wiz] segmentation of DMZs
    ... public as well as private boxes. ... In fact, separate zones can make some things easier, for instance when ... as they pass through the firewall, so that the response always passes ... "open ports x,y,z and 1024-65535 in both directions", etc. ...
    (Firewall-Wizards)
  • Re: Secure Network Design (DMZ, LAN, etc)
    ... separated from the dbs by a firewall - transparent or router (different ... Secure Network Design ... > then why have a separate network? ... > switch. ...
    (Security-Basics)
  • RE: Secure Network Design (DMZ, LAN, etc)
    ... You can't have separate subnets separated by a switch. ... is only because the firewall is going to be doing NAT in addition to ... > Subject: Re: Secure Network Design ...
    (Security-Basics)