Re: what about xp's firewall?

From: Bruce Chambers (bchambers_at_nospamcableone.net)
Date: 06/23/04


Date: Tue, 22 Jun 2004 19:37:25 -0600

Greetings --

    Well, WinXP's built-in ICF is certainly better than nothing, but
it's no substitute for a real firewall.

   WinXP's built-in firewall is _adequate_ at stopping incoming
attacks, and hiding your ports from probes. It doesn't give you any
alarms, or any other kind of indication, to tell you that it is
working, though. Nor is it very easily configurable. What WinXP also
does not do, is protect you from any Trojans or spyware that you (or
someone else using your computer) might download and install
inadvertently. It doesn't monitor out-going traffic at all, other
than to check for IP-spoofing, much less block (or at even ask you
about) the bad or the questionable out-going signals. It assumes that
any application you have on your hard drive is there because you want
it there, and therefore has your "permission" to access the Internet.
Further, because the ICF is a "stateful" firewall, it will also assume
that any incoming traffic that's a direct response to a Trojan's or
spyware's out-going signal is also authorized.

    ZoneAlarm, Kerio, or Sygate are all much better than WinXP's
built-in firewall, and are much more easily configured, and there are
free versions of each readily available. Even the commercially
available Symantec's Norton Personal Firewall is superior by far,
although it does take a heavier toll of system performance then do
ZoneAlarm or Sygate.

   To enable/disable the built-in firewall, Start > Network
Connections > Right-click the connection > Properties > Advanced >
Protect my computer.....

HOW TO Enable or Disable Internet Connection Firewall in Windows XP
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q283673

    If you're using AOL, MSN, NetZero, or another on-line content
providing service that doesn't trust its customers to control their
own computers and insists upon the installation of a proprietary
connectoid, you'll either need to find a 3rd party firewall that is
compatible with them, or switch to a real ISP that is compatible with
the real Internet.

Bruce Chambers

-- 
Help us help you:
http://dts-l.org/goodpost.htm
http://www.catb.org/~esr/faqs/smart-questions.html
You can have peace. Or you can have freedom. Don't ever count on
having both at once. - RAH
"Reece George" <reecegeorge@yahoo.com.au> wrote in message
news:40d8c1f5@news.comindico.com.au...
> I am generally confident that if someone is seriouse about getting
the data
> from my computer then it would have already have been gone.
>
> I am guessing the firewall in xp is there, just like we have locks
on our
> doors, to keep out the honest people, part-time crooks.
>
> Of course, I do switch the xp firewall on but does anyone here know
how good
> it is?
>
> How do you measure how good a firewall is anyway? Shouldnt you just
measure
> how unlucky the user is? :-)
>
> Reece
> http://www.reecegeorge.com
>
>


Relevant Pages

  • Re: avast
    ... > Just did a clean installation of xp pro sp1 and download 'avast anti ... Did you firewall before connecting to the internet? ... Internet and patch with the critical updates? ... Why you should use a computer firewall.. ...
    (microsoft.public.windowsxp.general)
  • Re: XP NOT RESPONDING
    ... Did you have a firewall going before connecting to the internet? ... Microsoft has these suggestions for Protecting your computer from the ... Why you should use a computer firewall.. ... are pay - some you can only download if you are registered - but it is best ...
    (microsoft.public.windowsxp.setup_deployment)
  • Re: Guide to secure installtion of IIS 5
    ... don't forget a well-configured firewall. ... Do not put the computer onto the network or the Internet until after the ... Follow the instructions for hardening Windows and IIS at ... Install all service packs and security fixes from Microsoft and otherwise ...
    (microsoft.public.inetserver.iis.security)
  • RE: firewall
    ... You need to do a lot of reading about ipfw ... IPFW is the only firewall available to FBSD, ... rules do not function correctly on a DSL or cable internet ... @320 pass in quick on rl0 proto tcp from 63.70.155.0/24 to any port ...
    (freebsd-questions)
  • Re: Security Alerts Driving Me INSANE!
    ... The only reason, really, that you need a firewall and antivirus software is ... because you use the Internet with your computer. ... cleaned up and considered a hardware upgrade or three. ...
    (microsoft.public.windowsxp.security_admin)