XP2 and router firewalls

K

Ken Wampach

From what I have seen in this group, the consensus seemed to be
that ICF was unnecessary if your LAN was behind a router with
the fire wall enabled. In my case, I have a D-Link DI-604 with
all ports blocked. I get "Full Stealth" mode from "Shields Up"
at www.grc.com after I routed Port 113 to 192.168.0.200 which is
well out of range of any of my machines. Their are 4 computers
on the network in a home office used only by my wife and me, so
I have things very open on the LAN.

My question is whether their is any need for the SP2 firewall in
this configuration, when, and if, I get up the courage to try
SP2?
 
R

Rich/rerat

Ken,
There should be no problem, after installing SP2, just turn off the SP2 firewall, it is enabled at the time of installation. I have the DI-624 wireless router, and that is what I did. You will need to go through all the Internet Options & Outlook Express settings, customize as you want. The SP2 pop-up blocker ain't too bad, but it may conflict with third party blockers, I just uninstalled the one I was using. You may just disable the SP2 blocker, and stick with one you are currently using, if applicable.

--

Add MS to your News Reader: news://msnews.microsoft.com
Rich/rerat

(RRR News) <message rule>
<<Previous Text Snipped to Save Bandwidth When Appropriate>>


From what I have seen in this group, the consensus seemed to be
that ICF was unnecessary if your LAN was behind a router with
the fire wall enabled. In my case, I have a D-Link DI-604 with
all ports blocked. I get "Full Stealth" mode from "Shields Up"
at www.grc.com after I routed Port 113 to 192.168.0.200 which is
well out of range of any of my machines. Their are 4 computers
on the network in a home office used only by my wife and me, so
I have things very open on the LAN.

My question is whether their is any need for the SP2 firewall in
this configuration, when, and if, I get up the courage to try
SP2?
 
C

Chuck

From what I have seen in this group, the consensus seemed to be
that ICF was unnecessary if your LAN was behind a router with
the fire wall enabled. In my case, I have a D-Link DI-604 with
all ports blocked. I get "Full Stealth" mode from "Shields Up"
at www.grc.com after I routed Port 113 to 192.168.0.200 which is
well out of range of any of my machines. Their are 4 computers
on the network in a home office used only by my wife and me, so
I have things very open on the LAN.

My question is whether their is any need for the SP2 firewall in
this configuration, when, and if, I get up the courage to try
SP2?

Ken,

A NAT router like the DI-604 is just the outermost layer of a good defense
strategy. The router provides protection against hostile incoming traffic only,
Each layer is necessary because no layer produces complete protection.

The second layer is a software firewall, or a port monitor like Port Explorer
(free) from <http://www.diamondcs.com.au/portexplorer/index.php?page=home>, on
each computer. You need this layer for protection against unknown software
generating unwanted outgoing traffic, and for protection against hostile traffic
from other computers on your LAN. Windows Firewall provides this protection as
do other third party products. See discussions in comp.security.firewalls for
more information.

The third layer is good software. This layer has multiple components.

AntiVirus protection. Realtime, plus a regularly scheduled virus scan.
Regularly updated.

Adware / spyware protection. Realtime, plus a regularly run adware / spyware
scan. Regularly updated.
Complete instructions, using Spybot S&D and HijackThis (both free) are here:
<http://forums.spywareinfo.com/index.php?showtopic=227>.

Harden your browser. There are various websites which will check for
vulnerabilities, here are three which I use.
http://www.jasons-toolbox.com/BrowserSecurity/
http://bcheck.scanit.be/bcheck/
https://testzone.secunia.com/browser_checker/

Block Internet Explorer ActiveX scripting from hostile websites (Restricted
Zone).
<https://netfiles.uiuc.edu/ehowes/www/main.htm> (IE-SpyAd)

Block known dangerous scripts from installing.
<http://www.javacoolsoftware.com/spywareblaster.html>

Block known spyware from installing.
<http://www.javacoolsoftware.com/spywareguard.html>

Make sure that the spyware detection / protection products that you use are
reliable:
http://www.spywarewarrior.com/rogue_anti-spyware.htm

Harden your operating system. Check at least monthly for security updates.
http://windowsupdate.microsoft.com/

Block possibly dangerous websites with a Hosts file. Three Hosts file sources I
use:
http://www.accs-net.com/hosts/get_hosts.html
http://www.mvps.org/winhelp2002/hosts.htm
(The third is included, and updated, with Spybot (see above)).

Maintain your Hosts file (merge / eliminate duplicate entries) with:
eDexter <http://www.accs-net.com/hosts/get_hosts.html>
Hostess <http://accs-net.com/hostess/>

Secure your operating system, and applications. Don't use, or leave activated,
any accounts with names or passwords with trivial (guessable) values. Don't use
an account with administrative authority, except when you're intentionally doing
administrative tasks.

The fourth layer is common sense. Yours. Don't install software based upon
advice from unknown sources. Don't install free software, without researching
it carefully. Don't open email unless you know who it's from, and how and why
it was sent.

The fifth layer is education. Know what the risks are. Stay informed. Read
Usenet, and various web pages that discuss security problems. Check the logs
from the other layers regularly, look for things that don't belong, and take
action when necessary.

Cheers,
Chuck
Paranoia comes from experience - and is not necessarily a bad thing.
 
S

Steve Winograd [MVP]

"Ken Wampach" said:
From what I have seen in this group, the consensus seemed to be
that ICF was unnecessary if your LAN was behind a router with
the fire wall enabled. In my case, I have a D-Link DI-604 with
all ports blocked. I get "Full Stealth" mode from "Shields Up"
at www.grc.com after I routed Port 113 to 192.168.0.200 which is
well out of range of any of my machines. Their are 4 computers
on the network in a home office used only by my wife and me, so
I have things very open on the LAN.

My question is whether their is any need for the SP2 firewall in
this configuration, when, and if, I get up the courage to try
SP2?

I'd run the SP2 firewall, too. Unlike XP's original Internet
Connection Firewall, the new Windows Firewall is easy to configure to
allow file and printer sharing on the LAN while blocking other,
undesired types of access between the LAN computers. For example, if
one LAN computer became infected with something like the Blaster worm,
the Windows Firewall would prevent the worm from infecting the rest of
the computers.
--
Best Wishes,
Steve Winograd, MS-MVP (Windows Networking)

Please post any reply as a follow-up message in the news group
for everyone to see. I'm sorry, but I don't answer questions
addressed directly to me in E-mail or news groups.

Microsoft Most Valuable Professional Program
http://mvp.support.microsoft.com
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top