Re: firewall behind router

Tech-Archive recommends: Speed Up your PC by fixing your registry

From: Lanwench [MVP - Exchange] (lanwench_at_heybuddy.donotsendme.unsolicitedmail.atyahoo.com)
Date: 08/28/04


Date: Sat, 28 Aug 2004 18:35:10 -0400

Lou wrote:
> Thanks for reply.
>
> FYI. I do have file/printer sharing activated and use it on all my lan
> computers. On one of my lan computers I am running XP Home with SP2
> installed and the Windows firewall activated.. The others lan
> computers run Windows 98 with no firewall. All have an active
> anitvirus program activated. All run behind the router with private
> addresses for all IP addresses. I do not need protection between my
> lan computers.

Then you probably don't need the windows firewall enabled. But I do suggest
you put a firewall in place between your internet router & your LAN.

> I have no problems connecting to internet from any
> computer nor between lan computers.
>
> What does NAT "acts as a firewall" but isn't a firewall mean in terms
> of exposure to problems relative to unsolicited activity from internet
> sites?

NAT is network address translation. It doesn't inspect packets. See
http://searchsecurity.techtarget.com/sDefinition/0,,sid14_gci212125,00.html
for one definition of what a firewall is....

>
> I do understand that Windows firewall provides protection for incoming
> but not outgoing net traffic.

Yep....if you get a hardware firewall, you can set it up to allow only those
outbound ports you wish (80, 443, 110, 25) as well as blocking all inbound
ports, and no computer will receive pesky popup notifications like "do you
want to allow X to access the Internet?". Of course, a firewall is not a
panacea, and should be only one part of your security strategy. Keeping all
computers patched to the gills with the latest critical updates and perhaps
upgrading the 9x PCs to XP as well would be a good step....as well as
keeping all antivirus software updated.
>
> Thanks again.
>
> Lou
>
> On Sat, 28 Aug 2004 15:39:39 -0400, "Lanwench [MVP - Exchange]"
> <lanwench@heybuddy.donotsendme.unsolicitedmail.atyahoo.com> wrote:
>
>> NAT "acts as a firewall" but isn't a firewall. Either put in a
>> decent SPI firewall (such as a NetGear FR114P) or install firewall
>> software on all clients and allow the local subnet free access if
>> you need file/printer sharing.
>>
>> Lou wrote:
>>> Is there a need for a firewall behind a router. My home network is
>>> configured with private addresses (i.e. 192.168.x.x). The router ip
>>> address which connects to the internet via cable modem is also
>>> private (192.168.0.142).
>>>
>>> Reason for question is I seem to recall private addresses are not
>>> accessible from the internet.
>>>
>>> Lou



Relevant Pages

  • Re: Problem after upgrading to SP2
    ... IDs with passwords is my Win2k machine and we can access that machine w/o ... >> Did you check to see if all the computers are part of the same ... >> network - not too sure it the Windows Firewall has this, as I use ZA Pro, ...
    (microsoft.public.windowsxp.security_admin)
  • Re: RD works on LAN not across Internet
    ... RD works fine within my LAN but not across the ... I turned off Windows Firewall and NIS on all computers. ... >>> settings to fully use DHCP to access the Internet. ...
    (microsoft.public.windowsxp.work_remotely)
  • Re: XP Firewall question
    ... I have turned off XP's firewall. ... Assuming you have a Lan network behind a router. ... all the computers on the Lan from attacks from the outside world. ...
    (microsoft.public.windowsxp.general)
  • Re: User account restriction error accessing a shared folder on my net
    ... > I have two computers both running WinXP. ... > Everything was going well until I installed SP2 on one of them. ... Service Pack 2 automatically enables the Windows Firewall. ...
    (microsoft.public.windowsxp.network_web)
  • Re: lan connection
    ... I linked, with a direct lan cable, two computers with O.S. ... Computer a can correctly ping itself through its ip and b ... With Windows Firewall, this means allowing File/Printer ...
    (microsoft.public.windowsxp.network_web)