Security question, firewall options
Security question, firewall options
Author
Discussion

TUS 373

Original Poster:

4,965 posts

299 months

Wednesday 11th February 2004
quotequote all
I am running a home network behind a wireless adsl modem/router/hardware fire wall and NAV A/V software on a desktop and wireless notebook. Is my online security adequate and what options do I have?

I used to run the standard Zonealarm product, but this effectively stopped file sharing and printer sharing between the computers and Zonealarm would block the port (?445). Would the Zonealarm Plus/Pro versions allow me to continue file/printer sharing and allow the machines to see one another?

Alternatively, I have enough redundant PC bits to build a Linux Smoothwall. Just not sure how I would physically connect that in between all the bits that I currently have ( phone/adsl line goes into router, router has 1 ethernet port that plugs into LAN on desk PC) - so where/how could I put in a Smoothwall. Is there even any point in this as the router is firewalled anyway??

Any advice would be welcomed.

>>> Edited by TUS 373 on Wednesday 11th February 11:24

Plotloss

67,280 posts

288 months

Wednesday 11th February 2004
quotequote all
Seems perfectly adequate to me.

I use the Norton Internet Security suite for my network and that seems fine also.

doug phillips

351 posts

264 months

Wednesday 11th February 2004
quotequote all
If you want to run a test on your computers, then go to www.grc.com and run shields-up. Then you can see if there are any "holes" in your network.

Doug,

slinksport

15,704 posts

267 months

Wednesday 11th February 2004
quotequote all
TUS 373 said:

Alternatively, I have enough redundant PC bits to build a Linux Smoothwall. Just not sure how I would physically connect that in between all the bits that I currently have ( phone/adsl line goes into router, router has 1 ethernet port that plugs into LAN on desk PC) - so where/how could I put in a Smoothwall. Is there even any point in this as the router is firewalled anyway??


Although Smoothie is a great solution (ran one for nearly a year) I feel it's overkill for your situation.. You've already got the router serving as a firewall, are you that worried about security that you need to go through the arse that is getting smoothie up and running completely!

Standard Zonealarm should allow you to continue to use file and printer sharing (AFAIR).. and a GRC scan should show you whether or not your firewall on the router is doing it's job..

If however you fancy running Smoothie in Red Orange Green configuration with a DMZ and full blown LIDS then go for it..

jodypress

1,980 posts

292 months

Wednesday 11th February 2004
quotequote all
i have a similar setup and use zone alarm. you can set ip ranges so that it allow the range that your router will set (if you are using its dhcp server) the only thing you have to do is once you have set it and applied changes. you must exit (shutdown) zonealarm and restart it. other wise if you restart your pc it loose all settings.
jody

tuffer

8,909 posts

285 months

Wednesday 11th February 2004
quotequote all
I ran a smoothie for a couple of years, easy enough to set up. Just plug your adsl modem into the pc running Smoothwall. Make sure you read ALL the docs for it.
Found it be far better than a router, there are ways and means of by-passing routers/NAT devices. Just got to be a pain in the arse having so many P's in the house so the wife said it had to go. Now use a DSL-604+ and having fun trying to get XP to work with wireless!!!

slinksport

15,704 posts

267 months

Wednesday 11th February 2004
quotequote all
Got rid of smoothie as I moved house and no longer have the need to host a webserver (that was the only real reason for having smoothie as I needed the DMZ)

Now it's just a NAT'd router into my hub and XP Firewall.. (just got to get the two mb line up and running now... no point in all this kit when I using 56k dial up! )

pdV6

16,442 posts

279 months

Wednesday 11th February 2004
quotequote all
TUS 373 said:
I used to run the standard Zonealarm product, but this effectively stopped file sharing and printer sharing between the computers and Zonealarm would block the port (?445). Would the Zonealarm Plus/Pro versions allow me to continue file/printer sharing and allow the machines to see one another?

Just add the IP address of your other PC as "trusted" in ZA. Robert's your mother's live-in lover.

whoozit

3,852 posts

287 months

Wednesday 11th February 2004
quotequote all
tuffer said:
Now use a DSL-604+ and having fun trying to get XP to work with wireless!!!


That drove me nuts as well. I found the best way was to run the networking wizard then choose the "other" option, then "connects through a hub" and that usually worked.

tuffer

8,909 posts

285 months

Wednesday 11th February 2004
quotequote all
AAAARRRRRRGGGGGGHHHHHH!

XP says 1 or more networks are available but it will not connect. Yes I have all the key etc set-up.
When I do an ipconfig /all it shows the wireless card as media disconnected. XP finds the driver and shows no problems, it "see's" the network but I cannot ping the card or connect!

tuffer

8,909 posts

285 months

Wednesday 11th February 2004
quotequote all
Anyone know the web site for Lucent Orinoco drivers, been looking but can fond nothing, anyone have an XP driver?

Marshy

2,751 posts

302 months

Wednesday 11th February 2004
quotequote all
Have you turned off 802.1x authentication in the connection properties? It's on by default and is a "buried" setting.

And on XP the driver it has for the Lucent cards is fine IIRC - and the Lucent client manager fights horribly with the Windows XP wireless autoconfig stuff. Certainly when I moved to XP, I ditched the Lucent software as it seemed unnecessary.