Tilted Forum Project Discussion Community

Tilted Forum Project Discussion Community (https://thetfp.com/tfp/)
-   Tilted Technology (https://thetfp.com/tfp/tilted-technology/)
-   -   Best Cheap Firewall (https://thetfp.com/tfp/tilted-technology/43045-best-cheap-firewall.html)

Astrocloud 01-26-2004 10:15 AM

Best Cheap Firewall
 
Anyone have any recommendations for a good inexpensive firewall? Either hardware or software as I am running cable modem and windows XP pro

cj22009 01-26-2004 11:14 AM

Get Zone alarm its free and Its a decent firewall

Moskie 01-26-2004 11:26 AM

I've been very happy with Agnitum Outpost firewall. I've gone through the rounds (Zone Alarm, Norton, a couple others) and Outpost is the only one that gave me level of control I liked. Check it out, there's a free version of it.

shakran 01-26-2004 11:37 AM

i'll second Outpost. Zone Alarm is nice, but it's got some bugs that can occasionally make your computer act weird.

sailor 01-26-2004 11:54 AM

I use Sygate Personal Firewall. Works well for me.

Jonah Hex 01-26-2004 03:14 PM

If you want to be secure get yourself a little 4 port router from netgear or dlink for about £40

http://www.netgear.com/products/prod...odID=131&view=

read the manual and set aside 4-5 hrs for install and setup and you will never regret it.

there is no real substitute.

ToolBag 01-26-2004 03:20 PM

Ive used Outpost and Zonealarm and it seemed that Outpost performed better but acted really wierd on my system. Zonealarm has run perfectly and does the job for me.

Pragma 01-26-2004 04:30 PM

NAT really isn't a firewall - it doesn't help the fact that you've got the machine unprotected - it just hides it behind another IP. The best firewalls are stateful and have some kind of mechanism to check packets for known-bad signatures (ie: Code Red packets).

Windows XP Service Pack 2's firewall is much improved over the original Internet Connection Firewall, but (for obvious reasons) most people wouldn't want to upgrade to a beta service pack of their OS.

cj2112 01-26-2004 04:43 PM

I run Xp home and used to run Sygate, however it made my system take forever to startup. I switched to Zone Alarm (and made no other changes) and my computer started up much much faster again. Sygate worked well for me, as does Zone Alarm both are free, the startup time was the only reason I switched.

nanofever 01-26-2004 08:38 PM

ZoneAlarm is your friend. ZoneAlarm Pro is like a friend, but more like a lover you can't ever see yourself leaving.

txd 01-27-2004 04:27 AM

If you have a spare machine knocking about (who doesnt :) ) you could look into installing OpenBSD as your gateway and using its firewall (pf) . Which among other things alows you to improve the speed of your ADSL Cconection

sixate 01-27-2004 05:17 AM

Zone Alarm is good, and free.
Zone Alarm Pro is great! But it isn't free. Although, it was for me. ;)
I never see stupid pop-ups, and I never get anything installed on my PC that shouldn't be there. I couldn't imagine not having ZAPro on my PC.

Bill O'Rights 01-27-2004 05:34 AM

I use Sygate. It works well, and it's free.

Pragma 01-27-2004 06:21 AM

Quote:

Originally posted by txd
If you have a spare machine knocking about (who doesnt :) ) you could look into installing OpenBSD as your gateway and using its firewall (pf) . Which among other things alows you to improve the speed of your ADSL Cconection
Excellent recommendation - I do that myself. Unfortunately, it does require a fairly good knowledge of UNIX before you can set up something like that - so it's not really applicable to most people

ratbastid 01-27-2004 06:39 AM

Quote:

Originally posted by Pragma
NAT really isn't a firewall - it doesn't help the fact that you've got the machine unprotected - it just hides it behind another IP.
That's not entirely true. There IS no route to internal machines from outside, except for explicitly forwarded ports. NAT allows internal machines to connect out transparently by proxy, but there's no way for Code Red or anything else to make its way to a machine on the internal network.

The reason you'd want to do it with a little router rather than a whole machine running a firewall is because there's nothing to hack in a little router. If I can crack a firewall box, I'm in the internal network. I can't crack a little home router because there's not really any OS there to crack. I mean, there's an embedded OS there, but I couldn't pull a shell on it. What answers on the IP that my cable service assigns is a router that doesn't respond on any port (except for a couple I've explicitly forwarded).

None of my internal machines have firewalls of any kind, and I've never been touched by Code Red, Messenger pop-ups, or anything else like that.

txd 01-27-2004 08:39 AM

Quote:

Originally posted by Pragma
Excellent recommendation - I do that myself. Unfortunately, it does require a fairly good knowledge of UNIX before you can set up something like that - so it's not really applicable to most people
Granted it may seem a bit daunting, but as long as the person doing it takes their time and is able to read a web page it should not be too hard.

The OpenBSD FAQ and man pages are great. A typical install takes about 30minutes to set up and have a firewall running.

God of Thunder 01-27-2004 11:34 AM

ratbastid speaks the truth.


I figure that pretty much covers it. :D


Hardware firewalls are much more secure that software ones and are resonbly inexpensive. They are easy to setup and are worth it.

I had my new wireless router set up and was surfing the net from upstairs ina matter of hours, and I went with the advanced configuration.

santafe5000 01-27-2004 02:33 PM

ZoneAlarm cause it's FREE. Have it on both my machines and it is easy to work with. I bought McAfee to install on my home machine but it was a pain to install and kept causing lockup problems. Never could get it to work right so pulled it and put ZoneAlarm on. No problems since.

Lasereth 01-27-2004 02:37 PM

Quote:

Originally posted by santafe5000
ZoneAlarm cause it's FREE. Have it on both my machines and it is easy to work with. I bought McAfee to install on my home machine but it was a pain to install and kept causing lockup problems. Never could get it to work right so pulled it and put ZoneAlarm on. No problems since.
I almost had to format because of the McAfee lockups. System Restore was turned on thankfully...I seriously would have had to format my PC because of an ANTIVIRUS program if I couldn't have rolled back. That program is the definition of bloatware.

-Lasereth

Cynthetiq 01-27-2004 02:45 PM

:) i'm all for hardware... and follow in ratbastids steps.

oberon 01-27-2004 04:07 PM

Quote:

Originally posted by ratbastid
That's not entirely true. There IS no route to internal machines from outside, except for explicitly forwarded ports. NAT allows internal machines to connect out transparently by proxy, but there's no way for Code Red or anything else to make its way to a machine on the internal network.

The reason you'd want to do it with a little router rather than a whole machine running a firewall is because there's nothing to hack in a little router. If I can crack a firewall box, I'm in the internal network. I can't crack a little home router because there's not really any OS there to crack. I mean, there's an embedded OS there, but I couldn't pull a shell on it. What answers on the IP that my cable service assigns is a router that doesn't respond on any port (except for a couple I've explicitly forwarded).

None of my internal machines have firewalls of any kind, and I've never been touched by Code Red, Messenger pop-ups, or anything else like that.

You don't need to get a shell to bypass a firewall. Assuming there are no bugs in their network stack, and no forwarded ports, though, it'll be very difficult to break through. It's a bad assumption to make that no non-routable packets will hit the external interface of a NAT router, by the way.

For this reason and others, NAT has nothing to do with security. A firewall, on the other hand, does.

It just so happens that every consumer "router" device has firewall functionality. :)

I know most of you are probably going to dismiss my points, but I thought it deserved mentioning anyway.

meembo 01-27-2004 05:47 PM

Gotta agree about getting a router. Cheap, small, upgradable firmware... It protects well from the outside, but ZoneAlarm (or something like it) protects well from some rouge program (virus, trojan, auto-updates, etc.) within the computer sending something out without your permission

ratbastid 01-27-2004 06:39 PM

Quote:

Originally posted by oberon
You don't need to get a shell to bypass a firewall. Assuming there are no bugs in their network stack, and no forwarded ports, though, it'll be very difficult to break through. It's a bad assumption to make that no non-routable packets will hit the external interface of a NAT router, by the way.

Fair enough. It's true, I wouldn't put Fort Knox behind a Linksys broadband router. But it's plenty good enough for my house, IMO.

Quote:

For this reason and others, NAT has nothing to do with security. A firewall, on the other hand, does.

It just so happens that every consumer "router" device has firewall functionality. :)

You got me there. And you're exactly right--it's not a function of NAT that there's no upstream route, it's a function of the relatively simple firewall built into the router.

Quote:

I know most of you are probably going to dismiss my points, but I thought it deserved mentioning anyway.
Now why would you say that? I was guilty of a bit of oversimplification in my post, but I'm never above being corrected.

Pragma 01-27-2004 10:00 PM

Quote:

Originally posted by ratbastid
That's not entirely true. There IS no route to internal machines from outside, except for explicitly forwarded ports.
Well, I was gonna make similar comments as oberon, but he beat me to it while I was away for the evening.

I've seen a fair number of routers with security flaws, and if you can compromise the router, you can then get into the machines inside.

Of course, the best firewall is to - instead of a cable going to your router - put a loopback plug in your NIC. Ah, security. You won't have any of those damned hackers getting at you now, oh no you won't. The internet will be a bit limited, though.

cradeg 01-28-2004 12:59 AM

i use kerio personal firewall .. excellent piece of software , more stable than sygate

oberon 01-28-2004 01:37 PM

ratbastid: Just like you said, it's not really all that important as a home firewall. So why worry too much, eh? :)

I only wanted to enlighten the ignorant.

Pragma: The best firewall is to disconnect all the cables from your computer. Kinda defeats the purpose, though. ;)

Pragma 01-28-2004 02:37 PM

Quote:

Originally posted by oberon
Pragma: The best firewall is to disconnect all the cables from your computer. Kinda defeats the purpose, though. ;)
Ah, but with a loopback plug, you'll have a link light - you'll THINK you're connected :D

saltfish 01-28-2004 03:59 PM

For anyone who is interested in checking your network for security.. This is a slow port scan that will check your firewall/connection for any vulnerabilities.

http://www.dslreports.com/secureme_go

You'll need to register, but it's worth the few seconds it takes.


-SF

Jephree 01-28-2004 05:27 PM

Zone Alarm Pro.. Free and works well.

Spyder_Venom 01-29-2004 12:01 PM

Sygate Personal Firewall, its free from thier website :D


All times are GMT -8. The time now is 11:01 AM.

Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0 PL2
© 2002-2012 Tilted Forum Project


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360