Technical Discussion
  >> DSL Hardware Discussion


Register (or login) on our website and you will not see this ad.


These posts have been archived and can no longer be replied to or modified.
  Print Thread
Standard User angel_dust
(newbie) Sun 15-Oct-06 15:56:02
Print Post

Router Firewall ???


[link to this post]
 
Hi Folks

I have been thinking about getting a new router ( BT Voyager 2110 or the Voyager 1500 ) and I don't now if I should get the one with a hardware fire wall built in.

Will it slow down my connection speed if I also have a software fire wall installed on the PC???

Standard User yarwell
(legend) Sun 15-Oct-06 16:01:33
Print Post

Re: Router Firewall ???


[re: angel_dust] [link to this post]
 
router firewalls are generally a good thing, no measurable speed impact.

Phil

MaxDSL user survey - results back online.

MaxDSL speeds - what do they all mean.
Standard User deleted
(deleted) Mon 16-Oct-06 10:51:31
Print Post

Re: Router Firewall ???


[re: angel_dust] [link to this post]
 
When you purchase a modem/router make sure it has the advanced security feature SPI (Stateful Packet Inspection) firewall and NAT (Network Address Translation) to protect your computer from the Internet nasties.
http://www.answers.com/topic/stateful-inspection

http://www.answers.com/topic/network-address-translation


Register (or login) on our website and you will not see this ad.

Standard User deleted
(deleted) Mon 16-Oct-06 11:49:25
Print Post

Re: Router Firewall ???


[re: deleted] [link to this post]
 
A good thing to do for enhanced security is to set up your router to create a DMZ entry for a network address that doesn't exist on your local network. Then if people try to scan ports at your IP address, you're effectively stealthed, because all port attacks get sent to the address in your network that doesn't exist.



Standard User deleted
(deleted) Tue 17-Oct-06 11:22:53
Print Post

Re: Router Firewall ???


[re: deleted] [link to this post]
 
Hi

In reply to:


A good thing to do for enhanced security is to set up your router to create a DMZ entry for a network address that doesn't exist on your local network. Then if people try to scan ports at your IP address, you're effectively stealthed, because all port attacks get sent to the address in your network that doesn't exist.




You don't need to do this as this what NAT is already doing. The big danger with doing this is you may find later you end up with the DMZ IP address issued out to you by DHCP. You could of course use fixed IP addresses or tell DHCP to tie an IP address to a MAC but it's simply not needed and adds more complication to your setup.

Essentially what you are doing by suggesting this is actually give a route for traffic to get through to your network, whereas not doing this means NAT never passes the traffic through. The DMZ trick is less secure not more secure.



  Print Thread

Jump to