Security Basics mailing list archives

Re: Windows 98 box is 'owned'


From: Glenn Sieb <ges () wingfoot org>
Date: Mon, 04 Oct 2004 15:03:30 -0400

GuidoZ said the following on 10/1/2004 1:15 AM:

While these are all good points, I'd like to make a clarification on one thing.

1)  Complete re-install of the OS with the addition of both a software
firewall (ZoneAlarm) and a Hardware Firewall (Linksys, Dlink, etc).

Linksys, Dlink, etc are routers, not firewalls. While they function
similar to a hardware firewall (providing NAT and blocking the systems
behind them from direct access), they are NOT a substitute for a real
hardware firewall (SonicWall, AlphaShield, etc) when required.
Although, I believe a router would be plenty for your mother. =)

People frequently toss around the term "hardware firewall" (including
vendors), applying it to ANY device that provides NAT translation. In
my eyes, it takes a lot more then NAT to make a firewall. Additional
protection such as SPI, Content filtering, VPN, PKI, etc make up a
true hardware firewall.
Netgear's are firewalls. SPI, NAT, etc.

DLink is also a firewall. I had a DI703 which did SPI.

There *are* just routers that do nothing but NAT--but a lot of these boxes *do* offer Firewalls as well.

Best,
Glenn

--
"They that can give up essential liberty to obtain a little temporary safety deserve neither liberty nor safety." ~Benjamin Franklin, Historical Review of Pennsylvania, 1759


Current thread: