Re: Use of firewall software in desktops

From: Andrew Mitchell (amitchel_at_removecasey.vic.gov.au)
Date: 03/29/04


Date: Mon, 29 Mar 2004 02:53:59 -0800


"WH" <whtoh@global.com> said

> Hi,
>
> I have a group of avid travelling users in my company. They will
> normally connect to the internet from a hotel or internet cafe
> connection and VPN to access internal resources.
>
> I figured out the best way to prevent trojans or viruses from spreading
> when these users connect the same machines when they are back into the
> office LAN, is to ask them to turn on some kind of personal firewall
> when they are connecting from a hotel or internet cafe.
>
> Can someone advise me the best way to approach this, and what kind of
> firewall software should I use???? I think Windows XP firewall is good
> enough,

Correct. The Windows XP built in firewall should be sufficient.
Some of the third party products are better for computer literate users, but
the majority are confused by messages like 'Application xxx is trying to
connect to host www.domain.com on port 384. Do you want to allow this' and
just click Yes anyway, so the additional safety is negated.

> but it gives problem when I tried to use VPN over the
> Internet........

What VPN client are you using? Maybe try using a third party firewall on your
own machine so it can tell you what ports are being used by the VPN client
and open those specific ports on the built in XP firewall for your general
users.

Andy.



Relevant Pages

  • Re: Webserver, DMZ, ports questions
    ... Internet accesible services like SMTP have a seperate ... DMZ or a third interface in the firewall. ... As far as source / destination ports goes. ... from the internet to my web server, ...
    (Focus-Microsoft)
  • Re: statefull inspection FW and hackers
    ... Stateful inspection can be best understood with security zones/level. ... most of the firewall dont allow anything to come from low ... This would mean that if internal user accesses internet ... In turn that will give to the attacker a way to understand what ports ...
    (Security-Basics)
  • Re: FIREWALL- worth the effort ?
    ... I only use internet intermitently and "pull the plug out" ... Do you have a home Cable/DSL Router? ... forward any ports from the outside world to your Macthrough ... The other function of a firewall is to prevent out bound ...
    (comp.sys.mac.system)
  • Re: Adding Programs w/ActiveSync 3.7
    ... > would be granted access to the internet. ... my firewall typically advises me that software is ... Activesync uses certain ports to communicate with the Pocket PC. ... install the software... ...
    (microsoft.public.pocketpc.activesync)
  • Re: avast
    ... > Just did a clean installation of xp pro sp1 and download 'avast anti ... Did you firewall before connecting to the internet? ... Internet and patch with the critical updates? ... Why you should use a computer firewall.. ...
    (microsoft.public.windowsxp.general)