Ad
News

SIP-Capable Firewalls From Ingate

Published on January 25, 2002

SIP (Session Initiation Protocol) is an Internet protocol for IP telephony, presence, instant messaging and audio/video conferencing. Read more

Top firewalls easily pierced

Published on December 14, 2000

Security analyst Steve Gibson has written and is giving away a simple Trojan horse capable of penetrating most major PC firewalls. Read more

Cisco warns of holes in PIX firewalls

Published on December 17, 2003

Network equipment maker Cisco Systems Inc. Read more

Cisco aims for IPv6 firewalls

Published on June 30, 2003

Attacking one of the key problems early adopters have had with IPv6 (Internet Protocol Version 6), Cisco plans to beef up security, adding support for stateful packet filtering of IPv6 traffic to its software and hardware firewall products in the first half of next year. Read more

Last Reviews & Articles

System Builder Marathon: Performance & Value

Published on November 28, 2008

We tightened the budget on this month’s enthusiast-level system while loosening our belt for the low-cost gamer box by a similar percentage. Today we gauge the effect of these changes on performance and value and compare to last month's machines. Read more

System Builder Marathon: $1,250 Enthusiast PC

Published on November 27, 2008

On this, the second day of our System Builder Marathon, Don turns down the price tag of his mid-range build looking for a sweet spot just above the $1,000 marker. Let's see what sort of hardware he found for it! Read more

System Builder Marathon: $625 Gaming PC

Published on November 26, 2008

This month's System Builder Marathon is all about your feedback to us. We've revamped our entry-level and mid-range PCs with new price points. Let's kick things off with what we think is the best value at a $625 price point! Read more

The State Of The Personal Computer

Published on November 25, 2008

Where were we in 2008 and where are we heading in 2009? In his State of the Personal Computer address, Alan Dang shares his insights as a user of three different platforms--Mac, Windows, and Linux. Read more

  Tom's Hardware UK and Ireland Forums » General Networking » Firewall » Diff b/w cheap and expensive firewalls
 

Diff b/w cheap and expensive firewalls

Advanced Search

There are 367 identified and unidentified users. To see the list of identified users, Click here



Word :   Username :  
 
Bottom
Author
 Thread : Diff b/w cheap and expensive firewalls
 
More Information

Archived from groups: comp.security.firewalls (More info?)

 

I was wondering if somebody could clarify the difference between a cheap
retail firewall, like a D-Link you might get at Staples, with professional
grade firewalls from Symantec or Watchguard. If there is no serving going
on behind the firewall, (ie, no virtual server passthrough), is there
really a difference in security? Doesn't this eliminate the need for
SPI? Are $600 firewalls harder to defeat than $40 firewalls? Is it just
the bells and whistles of logging and alerts?

Thanks,
tslugmo

--
Using Opera's revolutionary e-mail client: http://www.opera.com/m2/

Related Product

Register or log in to remove.

More Information

Archived from groups: comp.security.firewalls (More info?)

 

In article <opsb6dyxrnk1tkce@tslugmo.belkin>, anon@yeahright.com says...
> I was wondering if somebody could clarify the difference between a cheap
> retail firewall, like a D-Link you might get at Staples, with professional
> grade firewalls from Symantec or Watchguard.

You need to separate the idea that a router with NAT is a firewall from
what a real firewall is/does. Routers with NAT provide a blocking
service based on the NAT function, nothing else.

Firewalls may or may not use NAT and provide filtering of traffic based
on traffic type (not always a port number) and do it in both directions.

There is a huge difference between a router with NAT and a firewall of
any type.

> If there is no serving going
> on behind the firewall, (ie, no virtual server passthrough), is there
> really a difference in security? Doesn't this eliminate the need for
> SPI? Are $600 firewalls harder to defeat than $40 firewalls? Is it just
> the bells and whistles of logging and alerts?

Yes, in one case, there was as sorority that had a NAT system installed,
there were 6 machines that were infected with a virus that had it's own
SMTP server. The infected machines were sending out infected emails
directly form their systems, bypassing the internal SMTP server. Had a
real-firewall been installed (or properly configured high-end router)
SMTP would not have been permitted from the local devices (except the
SMTP server) to the internet, or it would have only been permitted from
the workstations to the ISP's SMTP server for outbound messages. A
generic router would not have prevented this problem from reaching the
world.

$600 firewalls, or any firewall that is a real firewall, is harder to
defeat when properly configured than ANY router with NAT and SPI or any
router with just NAT.

If you've been reading these groups for a couple weeks you would already
know this :-)

--
--
spamfree999@rrohio.com
(Remove 999 to reply to me)

More Information

Archived from groups: comp.security.firewalls (More info?)

 

If I don't want anything to initiate access to my network from outside,
besides normal responses to HTTP and SMTP requests, do I need to go beyond
NAT? If there's no server or remote access going on?

Thanks,
tslug

On Tue, 03 Aug 2004 21:59:36 GMT, Leythos <void@nowhere.com> wrote:

> In article <opsb6dyxrnk1tkce@tslugmo.belkin>, anon@yeahright.com says...
>> I was wondering if somebody could clarify the difference between a cheap
>> retail firewall, like a D-Link you might get at Staples, with
>> professional
>> grade firewalls from Symantec or Watchguard.
>
> You need to separate the idea that a router with NAT is a firewall from
> what a real firewall is/does. Routers with NAT provide a blocking
> service based on the NAT function, nothing else.
>
> Firewalls may or may not use NAT and provide filtering of traffic based
> on traffic type (not always a port number) and do it in both directions.
>
> There is a huge difference between a router with NAT and a firewall of
> any type.
>
>> If there is no serving going
>> on behind the firewall, (ie, no virtual server passthrough), is there
>> really a difference in security? Doesn't this eliminate the need for
>> SPI? Are $600 firewalls harder to defeat than $40 firewalls? Is it
>> just
>> the bells and whistles of logging and alerts?
>
> Yes, in one case, there was as sorority that had a NAT system installed,
> there were 6 machines that were infected with a virus that had it's own
> SMTP server. The infected machines were sending out infected emails
> directly form their systems, bypassing the internal SMTP server. Had a
> real-firewall been installed (or properly configured high-end router)
> SMTP would not have been permitted from the local devices (except the
> SMTP server) to the internet, or it would have only been permitted from
> the workstations to the ISP's SMTP server for outbound messages. A
> generic router would not have prevented this problem from reaching the
> world.
>
> $600 firewalls, or any firewall that is a real firewall, is harder to
> defeat when properly configured than ANY router with NAT and SPI or any
> router with just NAT.
>
> If you've been reading these groups for a couple weeks you would already
> know this :-)
>



--
Using Opera's revolutionary e-mail client: http://www.opera.com/m2/

More Information

Archived from groups: comp.security.firewalls (More info?)

 

In article <opsb7we9qck1tkce@tslugmo.belkin>, anon@yeahright.com says...
> If I don't want anything to initiate access to my network from outside,
> besides normal responses to HTTP and SMTP requests, do I need to go beyond
> NAT? If there's no server or remote access going on?

In "general" if you have a NAT device that also supports SPI, and you
have no ports forwarded inbound, and the device is not a wireless
device, then you are about as safe from unsolicited inbound as you can
get without buying a real firewall.

This method does nothing to control rouge web sites, infected email, or
already compromised machines in your network.

The NAT with SPI will ensure that only things your computer contacts
will be able to communicate with it.


--
--
spamfree999@rrohio.com
(Remove 999 to reply to me)

More Information

Archived from groups: comp.security.firewalls (More info?)

 

What about NAT w/o SPI? If that's not safe, can you explain why not?

Thanks for your patience,
tslug

On Wed, 04 Aug 2004 17:42:58 GMT, Leythos <void@nowhere.com> wrote:

> In article <opsb7we9qck1tkce@tslugmo.belkin>, anon@yeahright.com says...
>> If I don't want anything to initiate access to my network from outside,
>> besides normal responses to HTTP and SMTP requests, do I need to go
>> beyond
>> NAT? If there's no server or remote access going on?
>
> In "general" if you have a NAT device that also supports SPI, and you
> have no ports forwarded inbound, and the device is not a wireless
> device, then you are about as safe from unsolicited inbound as you can
> get without buying a real firewall.
>
> This method does nothing to control rouge web sites, infected email, or
> already compromised machines in your network.
>
> The NAT with SPI will ensure that only things your computer contacts
> will be able to communicate with it.
>
>



--
Using Opera's revolutionary e-mail client: http://www.opera.com/m2/

More Information

Archived from groups: comp.security.firewalls (More info?)

 

In article <opsb8g27pwk1tkce@tslugmo.belkin>, anon@yeahright.com says...
> What about NAT w/o SPI? If that's not safe, can you explain why not?

From what I understand, there are issues without SPI that allow an
attacker to ride the inbound port that is being used by the local and
remote client to communicate - this means that an anonymous system, if
it could determine what ports your computer was using to talk with
another computer, could ride in on that same port.

I could be wrong, it's not a area that I have studied. I have also never
seen a NAT system compromised by not having NAT w/SPI.


--
--
spamfree999@rrohio.com
(Remove 999 to reply to me)

Profile: stranger
More Information

Archived from groups: comp.security.firewalls (More info?)

 

Leythos wrote:

> In article <opsb8g27pwk1tkce@tslugmo.belkin>, anon@yeahright.com says...
>> What about NAT w/o SPI? If that's not safe, can you explain why not?
>
> From what I understand, there are issues without SPI that allow an
> attacker to ride the inbound port that is being used by the local and
> remote client to communicate - this means that an anonymous system, if
> it could determine what ports your computer was using to talk with
> another computer, could ride in on that same port.
>
> I could be wrong, it's not a area that I have studied. I have also never
> seen a NAT system compromised by not having NAT w/SPI.

You confuse SPI with TCP sequence numbers. No half-decent implementation is
vulnerable to that.
--
Mailman


-----= Posted via Newsfeeds.Com, Uncensored Usenet News =-----
http://www.newsfeeds.com - The #1 Newsgroup Service in the World!
-----== Over 100,000 Newsgroups - 19 Different Servers! =-----

More Information

Archived from groups: comp.security.firewalls (More info?)

 

In article <41118ee0_5@corp.newsgroups.com>, mailman@anonymous.org
says...
> Leythos wrote:
>
> > In article <opsb8g27pwk1tkce@tslugmo.belkin>, anon@yeahright.com says...
> >> What about NAT w/o SPI? If that's not safe, can you explain why not?
> >
> > From what I understand, there are issues without SPI that allow an
> > attacker to ride the inbound port that is being used by the local and
> > remote client to communicate - this means that an anonymous system, if
> > it could determine what ports your computer was using to talk with
> > another computer, could ride in on that same port.
> >
> > I could be wrong, it's not a area that I have studied. I have also never
> > seen a NAT system compromised by not having NAT w/SPI.
>
> You confuse SPI with TCP sequence numbers. No half-decent implementation is
> vulnerable to that.

Thanks for the correction, I knew there as something out there like
that, but I didn't remember what it was.

--
--
spamfree999@rrohio.com
(Remove 999 to reply to me)


  Tom's Hardware UK and Ireland Forums » General Networking » Firewall » Diff b/w cheap and expensive firewalls

Go to:
 

Google ads