Re: Firewall questions

From: Kent W. England [MVP] (kwe_at_mvps.org)
Date: 09/28/03


Date: Sun, 28 Sep 2003 09:53:39 -0700


The XP Internet Connection Firewall is a nice piece of work. It blocks
incoming connection requests and stealths your computer from common port
scans. It allows UPnP aware programs like Messenger to set up port holes
to permit specific incoming connections to listening ports. You simply
turn it on. But it doesn't watch what your applications are doing
outbound. And it blocks file and printer sharing, so it isn't any good
if you need file and printer sharing. It's designed for a single
computer directly connected to Internet.

The personal firewalls you mention block incoming traffic like ICF does,
but they don't allow UPnP-aware applications to setup port holes. They
do watch all of your applications and can limit what applications do,
but you have to know and understand what all the applications and
processes are before you can properly configure the personal firewall.
Some free personal firewalls, like Kerio, can upload a configuration
file, so if you choose that product you can offload the configuration
headache to someone else by using their configuration file. (I have an
XP Kerio configuration file, for example, that covers a lot of
applications in a plain vanilla XP install.)

Sometimes just the awareness that you have a new application trying to
contact some port on the Internet is sufficient to alert you to spyware
or trojans. However, there are some malwares that can disable ZoneAlarm
(or try to). It's a never-ending battle of wits and twits.

-- 
Kent W. England, Microsoft MVP for Windows
"M.R" <M.R@M.R.com> wrote in
message news:0ac801c385cf$48adf3b0$a001280a@phx.gbl...
> I have been trying to infom myself reading these posts
> about firewalls- I already put the firewall using my
> internet connection by clicking "properties" on it- I am
> guessing that I set up a firewall on my operating system
> (which is Win. XP)- But I keep reading  about getting a
> firewall like, zonealarm for example. does one need to
> install one besides what I already have done- what is the
> difference to do one or both. And finally, where can I
> read about "what are the advantages & disadvantages of
> doing these firewalls"- I am a super novice so the
> terminology is hard to understand sometimes- thanks for
> any help


Relevant Pages

  • Re: AS4.2/WM5/OUTLOOK2K3 suddenly not syncing, please help
    ... there is a connection EXIST between the device because I ... connection on port 26675 but on the PPC the port number keeps ... Outlook, countless times of reinstalling Activesync, removing Windows ... Firewall set to NO). ...
    (microsoft.public.pocketpc.activesync)
  • RE: FTP Window of opportunity?
    ... target on the line when in reality it was just a firewall lying to them. ... The connection connects and then immediately ... Subject: FTP Window of opportunity? ... the FTP port shows up. ...
    (Pen-Test)
  • Re: WDSC, VPN, and RPG Editing
    ... With some machines I can have a 24 hour connection, ... thru port 23 using telnet. ... iSeries server to make sure they are configured to allow the ... through the firewall. ...
    (comp.sys.ibm.as400.misc)
  • Re: Plausible reasons for http access?
    ... The word port has several meanings, ... On my home firewall, I normally have _ALL_ logging off. ... NetBIOS is a protocol meant for local use within a windoze workgroup. ... If you block the connection (or ...
    (comp.security.misc)
  • Re: Problem with AS 4.1 and USB
    ... I have as said in my first post, set in my firewall to allow both tcp/udp ... Where do find the USB to check on phone? ... > And a UDP outgoing port of. ... >>> Connection? ...
    (microsoft.public.pocketpc.activesync)