To register for an Internet.com membership to receive newsletters and white papers, use the Register button ABOVE.
To participate in the message forums BELOW, click here


EIT Planet's Security News
 Symantec Warns of New Security Breach
 Security Vulnerabilities Prove Increasingly Costly
 IPS Market Approaches $1 Billion

Security Products
 BugBopper (BugBopper)
 VBA Password Remover Tool (VBA Password Remover)
 VBA Password Remover Software (VBA Password Remover Software)
 Free keylogger download (Free keylogger download)
 Monitoring Software (Monitoring software)
 Retrieve Outlook 2007 Password (Retrieve PST Password)


Go Back   Antionline Forums - Maximum Security for a Connected World > Security Discussions > Network Security Discussions

Network Security Discussions Discuss security issues related to routers, switches, etc., & protocols.

Reply
 
Thread Tools Display Modes
Old January 11th, 2010, 08:13 AM   #1
asegur
Junior Member
 
Join Date: Jan 2010
Posts: 1
asegur is on a distinguished road
Firewall and router

I have a simple question. Why should it be necessary to put a firewall protecting a network, if the router is already closing the unnecessary ports?
Thanks
asegur is offline   Reply With Quote
Old January 11th, 2010, 11:00 AM   #2
CybertecOne
Keeping The Balance
 
CybertecOne's Avatar
 
Join Date: Aug 2004
Location: Australia
Posts: 608
CybertecOne has a brilliant futureCybertecOne has a brilliant futureCybertecOne has a brilliant futureCybertecOne has a brilliant futureCybertecOne has a brilliant futureCybertecOne has a brilliant futureCybertecOne has a brilliant futureCybertecOne has a brilliant futureCybertecOne has a brilliant futureCybertecOne has a brilliant futureCybertecOne has a brilliant future
A simple answer in this case - the router IS the firewall.

The router is a hardware firewall, as opposed to a software firewall (application such as Sygate or Zonealarm).

I always prefer using a router or hardware firewall, unless a proxy/ISA is ideal (software running on a dedicated server). Such things are used after consideration of the existing/future network.
__________________
Space For Rent
CybertecOne is offline   Reply With Quote
Old January 11th, 2010, 05:56 PM   #3
instronics
Antionline's Security Dude
 
instronics's Avatar
 
Join Date: Dec 2002
Posts: 867
instronics has a reputation beyond reputeinstronics has a reputation beyond reputeinstronics has a reputation beyond reputeinstronics has a reputation beyond reputeinstronics has a reputation beyond reputeinstronics has a reputation beyond reputeinstronics has a reputation beyond reputeinstronics has a reputation beyond reputeinstronics has a reputation beyond reputeinstronics has a reputation beyond reputeinstronics has a reputation beyond repute
Apart from that, a real firewall is SO MUCH MORE than just something that closes ports from the outside. It all comes down to what you want to protect, and how much time/effort your willing to invest. Whilst for a simple home network, a simple router with firewalling functions might suffice, it is far from being a real firewall with tighter security.

There are many different types of firewalls, that offers different types of security. Dont forget that a large risk in computer security happens also from the inside, and not only from the outside.

Cheers.
__________________
Ubuntu-: Means in African : "Im too dumb to use Slackware"
instronics is offline   Reply With Quote
Old January 13th, 2010, 02:51 AM   #4
keezel
0_o Mastermind
 
keezel's Avatar
 
Join Date: Jun 2003
Location: Atlanta
Posts: 1,009
keezel has a reputation beyond reputekeezel has a reputation beyond reputekeezel has a reputation beyond reputekeezel has a reputation beyond reputekeezel has a reputation beyond reputekeezel has a reputation beyond reputekeezel has a reputation beyond reputekeezel has a reputation beyond reputekeezel has a reputation beyond reputekeezel has a reputation beyond reputekeezel has a reputation beyond repute
Quote:
Dont forget that a large risk in computer security happens also from the inside, and not only from the outside.
I'll echo this. A software firewall will prompt and alert you to unusual/new inbound and outbound traffic. Awareness is key. Some decent routers also maintain logs, but they are harder to read. Software firewalls running on your own computer tend to be much more user friendly.
__________________


http://tazforum.thetazzone.com/
keezel is offline   Reply With Quote
Old January 20th, 2010, 03:56 AM   #5
D0pp139an93r
Bąnned
 
D0pp139an93r's Avatar
 
Join Date: May 2003
Location: St. Petersburg, FL
Posts: 1,597
D0pp139an93r has a reputation beyond reputeD0pp139an93r has a reputation beyond reputeD0pp139an93r has a reputation beyond reputeD0pp139an93r has a reputation beyond reputeD0pp139an93r has a reputation beyond reputeD0pp139an93r has a reputation beyond reputeD0pp139an93r has a reputation beyond reputeD0pp139an93r has a reputation beyond reputeD0pp139an93r has a reputation beyond reputeD0pp139an93r has a reputation beyond reputeD0pp139an93r has a reputation beyond repute
Firewall is nothing more than a network traffic light. It allows packets based on simple set of rules, and denies everything else.

The security of each host is dependant on the configuration of the individual host. My own thoughts on software firewalls and OS configurations are relatively well known and probably outside the scope of this thread, so I'll leave it as it is.

Software firewalls are useless, especially behind a hardware solution. By the time malicious traffic is outbound, you've already failed.

The attack vectors that you need to worry about are the ones that come through established connections. Messengers, browsers, and other networked applications.

By limiting those application's access and permissions within the system, you can create a system that doesn't need the possibly exploitable software nonsense that modern PCs are full of.
__________________
A conspiracy of one...
D0pp139an93r is offline   Reply With Quote
Old January 28th, 2010, 10:31 AM   #6
MURACU
AO Guinness Monster
 
MURACU's Avatar
 
Join Date: Jan 2004
Location: paris
Posts: 988
MURACU has a reputation beyond reputeMURACU has a reputation beyond reputeMURACU has a reputation beyond reputeMURACU has a reputation beyond reputeMURACU has a reputation beyond reputeMURACU has a reputation beyond reputeMURACU has a reputation beyond reputeMURACU has a reputation beyond reputeMURACU has a reputation beyond reputeMURACU has a reputation beyond reputeMURACU has a reputation beyond repute
I would view it like this : A router needs to be configured to block traffic while a firewall needs to be configured to allow traffic. You can configure the router as a firewall but it tends to result in a fairly complicated configuration on the router. Also it can complicate troubleshooting network issues. Of course at the end of the day it will depend on the resources you have a vailable and the size of your network.
Cheers
Muracu
__________________
\"America is the only country that went from barbarism to decadence without civilization in between.\"
\"The reason we are so pleased to find other people\'s secrets is that it distracts public attention from our own.\"
Oscar Wilde(1854-1900)
MURACU is offline   Reply With Quote
Old January 29th, 2010, 07:30 AM   #7
CyberB0b
Senior Member
 
Join Date: Nov 2001
Posts: 100
CyberB0b is a splendid one to beholdCyberB0b is a splendid one to beholdCyberB0b is a splendid one to beholdCyberB0b is a splendid one to beholdCyberB0b is a splendid one to beholdCyberB0b is a splendid one to beholdCyberB0b is a splendid one to behold
Software firewalls are far from useless. A software firewall is important to protect you from what is inside the network. NAT routers only protect you from what's outside. If you have an infected machine on your network or are using wifi hotspots you need a software firewall to protect you from intrusions coming from inside the LAN.
__________________
sandwich.
CyberB0b is offline   Reply With Quote
Old January 29th, 2010, 08:07 PM   #8
nihil
Super Moderator: GMT Zone
 
nihil's Avatar
 
Join Date: Jul 2003
Location: United Kingdom: Bridlington
Posts: 15,990
nihil has a reputation beyond reputenihil has a reputation beyond reputenihil has a reputation beyond reputenihil has a reputation beyond reputenihil has a reputation beyond reputenihil has a reputation beyond reputenihil has a reputation beyond reputenihil has a reputation beyond reputenihil has a reputation beyond reputenihil has a reputation beyond reputenihil has a reputation beyond repute
Hi,

As said above, but please consider this:

If you don't have it and things go wrong YOU are fired..............otherwise you did "industry standards"....

There are some on this site who might advise otherwise, from their self-perceived high and mighty positions....... I have seen them crap out in court.......... probably flipping burgers now

Sysadmin is basically middle management at best , and most know jack sh1t about management at that, at least the cutthroat nature of some of it

I can give you some case examples of your question.......... but I will leave them for the moment............

EDIT:

I realise that I probably sound somewhat defeatist, but I am a firm believer in "CYA" or "due diligence"............. whatever you like to call it.

I wouldn't like to explain to a CEO why I had decided against a firewall, when he has probably heard of those, but knows nothing about routers. It is a bit like the arguments for and against AV products.........sure, they may not do much for you, but they are an insurance policy for your job?

Quote:
if the router is already closing the unnecessary ports?
That still leaves you with the issue of what traffic is allowed through the ports you need to keep open?

OK, some quality routers also act as a hardware firewall as well, and at the risk of sounding pedantic, I would describe them as combo products rather than just a router.

Some very good points were made about the "enemy within"...............typically your router and hardware firewalls are at the perimeter. You may decide to deploy internal firewalls in certain circumstances...............possibly in a school or college environment?
__________________
If you cannot do someone any good: don't do them any harm....
As long as you did this to one of these, the least of my little ones............you did it unto Me.

Last edited by nihil; January 30th, 2010 at 10:26 AM..
nihil is offline   Reply With Quote
Old February 1st, 2010, 10:04 AM   #9
CybertecOne
Keeping The Balance
 
CybertecOne's Avatar
 
Join Date: Aug 2004
Location: Australia
Posts: 608
CybertecOne has a brilliant futureCybertecOne has a brilliant futureCybertecOne has a brilliant futureCybertecOne has a brilliant futureCybertecOne has a brilliant futureCybertecOne has a brilliant futureCybertecOne has a brilliant futureCybertecOne has a brilliant futureCybertecOne has a brilliant futureCybertecOne has a brilliant futureCybertecOne has a brilliant future
To explore yet another view point, a router connects your LAN to the internet. A Firewall has the domain over traffic control.

Now, in a small SOHO network, a router is needed to connect the network to the internet, and due to the size and nature of the network, a single firewall at the LAN WAN interface is needed - the router would do fine here....

However, ideally you are wanting to firewall protect every segment of the network that is critical. In a large network, multiple firewalls would be utilised, and some to protect only a single server..... another firewall to protect the workstations (on the same physical or logical network) and yet another firewall to protect the file server, as well as a WAN LAN interface firewall....... and each would be configured uniquely depending on the requirements of communication between each 'firewall protected' segment of the network.

Ideally....

Anyway, my point is when exploring the debate from this point of view, a router is needed to translate between the LAN and WAN only, whilst a firewall will do the protecting and traffic flow at various points throughout the network. From this point of view, the router and the firewall roles cannot be interchanged.
__________________
Space For Rent
CybertecOne is offline   Reply With Quote
Old February 4th, 2010, 01:59 PM   #10
morganlefay
AOs Resident Troll
 
Join Date: Nov 2003
Posts: 3,055
morganlefay has a reputation beyond reputemorganlefay has a reputation beyond reputemorganlefay has a reputation beyond reputemorganlefay has a reputation beyond reputemorganlefay has a reputation beyond reputemorganlefay has a reputation beyond reputemorganlefay has a reputation beyond reputemorganlefay has a reputation beyond reputemorganlefay has a reputation beyond reputemorganlefay has a reputation beyond reputemorganlefay has a reputation beyond repute
To quote an very wise ex AOer catch

"there is no such thing as a hardware firewall"

in essence because these devices are run by software :biggrin:

Use both....router to protect from external threats and the computer firewall to protect from internal.

MLF
morganlefay is offline   Reply With Quote
Reply

Bookmarks

Tags
firewall, ports, router

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Tips XTC46 Site Suggestions 15 August 24th, 2005 07:52 PM
Looking to protect yourself? mjk Firewall & Honeypot Discussions 6 March 12th, 2004 04:40 AM
Firewall security flaws by Sharepro Zato Firewall & Honeypot Discussions 2 February 1st, 2004 12:01 PM
firewall detection and network probing heatwave AntiOnline's General Chit Chat 2 October 10th, 2003 11:39 AM
Traceroute: under the hood antihaxor Non-Security Archives 0 January 24th, 2002 04:42 PM


All times are GMT +1. The time now is 04:05 PM.












Acceptable Use Policy

Internet.com
The Network for Technology Professionals

Search:

About Internet.com

Legal Notices, Licensing, Permissions, Privacy Policy.
Advertise | Newsletters | E-mail Offers

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.