|
|
![]() |
|
|
Top | #1 |
|
OSNN Veteran Addict
Joined: May 2002
Location: London England
Posts: 1,014
Reputation: 140
Power: 130 |
Anyone got any views on this?
|
|
|
|
|
|
Top | #2 |
|
Godlike!
Joined: February 2004
Location: Salisbury, Wiltshire, UK
Posts: 7,015
Blog Entries: 5
Reputation: 4137
Power: 209 |
you do not need a software firewall if you connect through a nat router. at all. ever.
|
|
|
|
|
|
Top | #3 |
|
- geek -
Joined: September 2003
Location: NY, USA
Posts: 5,216
Reputation: 1730
Power: 171 |
Originally Posted by LordOfLA
Unless he's on a Windows box and wants to keep programs from "phoning home" or trojans or what have you. I don't think I would run a Windows box without something doing some sort of packet inspection.
|
|
|
|
|
|
Top | #4 |
|
OSNN Veteran Addict
Joined: January 2003
Location: Fort Worth, TX
Posts: 5,255
Reputation: 3386
Power: 196 |
There are earlier posts here about the same subject.
Hardware (NAT) firewalls only protect against inbound traffic from the internet. Software firewalls protect against outbound traffic (worms. spyware, keystroke loggers, etc.) as well as inbound traffic looking for vulnerabilities. They also protect you from cross infection of computers on your own lan. Software firewalls are also updated as soon as new vulnerability types are identified. So if you're feeling lucky and are absolutely positive nothing will ever get onto a machine on your LAN, or if you don't care about a worm with a keystroke logger capturing your credit card numbers, social security number etc and broadcasting out to the web, or if you cut all the floppy, cd, usb hardware and the email accounts off your LAN PC's then sure, go ahead and depend on just the Router's NAT firewall. PS I do that on one machine on my LAN but the rest use soft and hard firewalls. |
|
|
|
|
|
Top | #5 |
|
Glaanies script monkey
Joined: February 2003
Location: Chicago
Posts: 2,725
Reputation: 1520
Power: 152 |
Also, you need a firewall if you want to protect against other PC's inside the LAN. If a PC is infected with some trojan, it could possibly infect all of your non-protected PC's in the network the same as a non-firewalled PC gets infected via the WWW.
|
|
|
|
|
|
Top | #6 |
|
OSNN Veteran Addict
Joined: May 2002
Location: London England
Posts: 1,014
Reputation: 140
Power: 130 |
Yes that’s what I thought, NAT’s do not check (by default) outgoing packets except to edit the header to amend the IP address. If this is true then setting then up correctly would take about a hundred years for each thousand PC’s on the internal network where a key logger already is installed.
Something’s adrift here surely?
|
|
|
|
|
|
Top | #7 |
|
OSNN Godlike Veteran
Joined: January 2002
Location: new york
Posts: 12,231
Reputation: 4333
Power: 288 |
Originally Posted by LordOfLA
I would never have a box running without outbound monitoring and protection
|
|
|
|
|
|
Top | #8 |
|
OSNN Veteran Addict
Joined: May 2002
Location: London England
Posts: 1,014
Reputation: 140
Power: 130 |
Just re-installed kaspersky software firewall and it shut down my internet connection immediately. I have disabled it pending a look through the logs and so I can post this.
|
|
|
|
|
|
Top | #9 |
|
Godlike!
Joined: February 2004
Location: Salisbury, Wiltshire, UK
Posts: 7,015
Blog Entries: 5
Reputation: 4137
Power: 209 |
okay so you load a software firewall, you get a virus that your AV software missed becuase it hasnt fetched the latest patterns yet, it kills your firewall (there are a few Win32API calls that will terminate an app and it doesn't get to argue about it) and happily sends it stuff about..
That protected you from outbound traffic how exactly? |
|
|
|
|
|
Top | #10 |
|
Glaanies script monkey
Joined: February 2003
Location: Chicago
Posts: 2,725
Reputation: 1520
Power: 152 |
The non infected PC's are now protected.
![]() I like to not have WMP call home every time it runs, I can block its traffic, also, alot of spyware/viruses do not disable firewalls and you can pick up on them rather easily when some odd new EXE is trying to reach the WWW. |
|
|
|
|
|
Top | #11 |
|
OSNN Godlike Veteran
Joined: January 2002
Location: new york
Posts: 12,231
Reputation: 4333
Power: 288 |
Originally Posted by LordOfLA
a person with a hardware firewall isn't protected agains viruses by virtue of his firewall
if a person has a hardware firewall that doesn't guard against outgoing traffic it's also neccessary to have a software firewall running with it...always plus, modern sofrware firewalls have sandboxes that refuse to allow exe's to run without permission, so a software firewall can prevent a virus while a hardware firewall won't |
|
|
|
|
|
Top | #12 |
|
█▄█ ▀█▄ █
Joined: December 2003
Location: Sterling Heights, MICHIGAN
Posts: 3,505
Blog Entries: 19
Reputation: 2905
Power: 164 |
Originally Posted by perris
agree...
|
|
|
|
![]() |
| Bookmarks |
| Thread Tools | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Who knows maybe it is Software, maybe its Hardware | Vanquished | Windows Desktop Systems | 14 | November 14th, 2006 2:26am |
| Hardware Tracking Software | omg its nlm | Green Room | 3 | September 20th, 2006 12:22am |
| Hardware Firewall | Capricorn | Windows Desktop Systems | 6 | November 6th, 2003 6:30pm |
| Hardware/Software Firewall? | Capricorn | Windows Desktop Systems | 3 | October 28th, 2003 11:22am |
| HARDWARE Firewall Advice | ZipTriX | Windows Desktop Systems | 5 | May 21st, 2002 10:27am |