O
Owen Newcomer
How can I disable messenger? I am using Windows XP.
Owen
Owen
Dan said:WinXP Home doesn't have the advanced tab...
I already triewd looking for it several times in all of my NIC
connections...
Walter Clayton said:Correctly configured, one and only one firewall will capture all intrusions
without letting anything through to a second firewall. That's why running a
firewall on machines on a LAN behind a router with an SPI firewall doesn't
gain anything. The issue with running two firewalls is that all traffic is
being vetted twice which is literally double the overhead for no additional
security.
And yes, I can actually configure ZA to run in high security on a LAN as
well as a WAN, but it's not a simple process. What you've done with ZA is
open the barn doors which is why Sygate is trapping traffic as well.
Disabling a bridge is not the same thing as deleting it. Disabling a bridge
disables all associated NICs which is a completely different thing.
Setting that aside, lets look at topology. In crude diagrams your
configuration should be something along the lines of one of the following:
[WAN]--->[PC1]-->[PC2]
[WAN]-->[Router]-->[PC1]
-->[PC2]
[WAN]-->[HUB]-->[PC1]
-->[PC2]
Notice on the last two that there is a major difference between the function
of a router and a hub. Also, there are variations on the theme that I have
seen some people attempt. These invariably have a lot of problems.
--
Walter Clayton - MS MVP(WinXP)
Associate Expert
http://www.microsoft.com/windowsxp/expertzone
Any technology distinguishable from magic is insufficiently advanced.
http://www.dts-l.org
soDan said:Walter and All --
Thank you so much for all your help!
So, if I understand what you are saying:
- I don't need the ICF on a LAN, only WAN
- Bridging is a nightmare (which I knew, but just verifying that fact)
Multiple firewalls are working great with my network. I correctly
configured Zone Alarm (free) to work with the LAN, so that was never an
issue. Sygate always worked with the LAN, so never an issue. Both combined
are awesome, because Sygate catches all the intrusions (ZA gets most) and
they do two checks for program security, in case something got past one, the
other catches it.
Notes on config ZA for LAN use:
- Under "Firewall" (Main tab) set Internet zone security to High, set
Trusted zone security to Low
- Under "Program Control" (Main tab) set Program Control to Medium
- These set it up to work beautifully with a LAN
The only thing I am still not sure about is a.) wether to to remove my
bridge and b.) what you meant by topology of my network. Last time I
disabled the bridge, my computer's Inet Connection went completely down, and
I reenabled it ASAP. Any issues/thoughts/comments on this?
Thanks again!
-- Dan
will
try dealing
with of the
LANneedI kinddo my
NIC
Walter Clayton said:OK. Delete the bridge. Each machine has a single connection and that
connection is to the router.
And yes, uninstall ZA.
Before I go much further, I need to know what you use the server for in
general terms. Are you running a server for internet access by others or is
it strictly for LAN access only? Do you use it as a work station at the same
time to access the internet?
--
Walter Clayton - MS MVP(WinXP)
Associate Expert
http://www.microsoft.com/windowsxp/expertzone
Any technology distinguishable from magic is insufficiently advanced.
http://www.dts-l.org
Dan said:I am running a server, so that is my reason for running firewalls on the
computer even though its behind a router.
Both Zone Alarm and Sygate catch the same intrusions and programs, so I
think maybe I can delete Zone Alarm (?) since Sygate actually shows attack
ip's, times, types, etc. and is (in my opinion) better than ZA.
The Topology of my Lan:
[WAN] --> [Router] --> [PC1 - Win98]
--> [Server - WinXP]
Thanks
-- Dan
Walter Clayton said:OK. Delete the bridge. Each machine has a single connection and that
connection is to the router.
And yes, uninstall ZA.
Before I go much further, I need to know what you use the server for in
general terms. Are you running a server for internet access by others or is
it strictly for LAN access only? Do you use it as a work station at the same
time to access the internet?
--
Walter Clayton - MS MVP(WinXP)
Associate Expert
http://www.microsoft.com/windowsxp/expertzone
Any technology distinguishable from magic is insufficiently advanced.
http://www.dts-l.org
Dan said:I am running a server, so that is my reason for running firewalls on the
computer even though its behind a router.
Both Zone Alarm and Sygate catch the same intrusions and programs, so I
think maybe I can delete Zone Alarm (?) since Sygate actually shows attack
ip's, times, types, etc. and is (in my opinion) better than ZA.
The Topology of my Lan:
[WAN] --> [Router] --> [PC1 - Win98]
--> [Server - WinXP]
Thanks
-- Dan