Re: Windows 2003 Packet Filter vs Firewall

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



In order to judge "efficiency" we would have to know much much more.
Basically you would have post your entire security policy (I know you
probably don't have one) and your operational requirements and your network
design.

But...

A firewall (yes, a real firewall, not a simple NAT device router) can
inspect the actual protocol and data on a given port and you can make rules
to allow/disallow access in either direction based on port "content", source
and destination addresses, usersIDs in some cases, and more, not just ports.
W2K3 does just ports.

-Frank

"MrDom" <mr_dom_is@xxxxxxxxxxx> wrote in message
news:1125756000.384302.35080@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
> Just wondered if any one could throw some light on this:
>
> Basically which was is best to have?, Windows 2003 TCP/IP Filtering
> running and only allowing traffic on selected ports, or the Firewall
>
> Which is more efficent?
>
> Thanks
>


.



Relevant Pages

  • Re: Root exploit for FreeBSD
    ... for two ports to my FreeBSD portscluster nodes. ... and it gives the firewall ... US this is also quite common, at least with regards to University ... if your computer is going to connect on our network it must be configured in certain ways and behave "normally" or you won't get a connection. ...
    (freebsd-questions)
  • Re: Root exploit for FreeBSD
    ... for two ports to my FreeBSD portscluster nodes. ... and it gives the firewall ... US this is also quite common, at least with regards to University ... if your computer is going to connect on our network it must be configured in certain ways and behave "normally" or you won't get a connection. ...
    (freebsd-current)
  • Re: Trouble accessing Outlook Web Access from behind firewall
    ... When starting the firewall I also set ... > rejected and dropped packets are logged, however I see nothing in my log ... > # Higher ports needed to accept incoming/outgoing calls ...
    (comp.security.firewalls)
  • Re: iptables configuration
    ... >> that if a 'virus/trojan' initiated a connection to the net, the firewall ... >> would not protect the LAN. ... The LAN is NATed with private IPs to one public IP. ... the ports that are used by services running on linux. ...
    (comp.os.linux.security)
  • Re: How to stealth against ping/echo requests?
    ... I just started using the Online-Armor firewall. ... Some ports are even open. ... Are you behind a router? ... Every time it founds a new LAN, it asks if you want to trust it ...
    (comp.security.firewalls)