Is a cheap router secure enough for small business

May 09, 2005 18 Replies

Hi,



We're going to have adsl internet at the small business office I work with. We need a router to share it with all PCs of the network. I'm familiar with the D-Link DI-784 and I think it would do a great job at this.



I'm wondering if the firewall included in this router will be secure enough to prevent intrusions and hacking of our network. Or do we absolutely need to buy a 2000$ firewall to sleep tight at night? I wouldn't like to spend much money on this.



Any ideas?



NeilSanner


I'm talking about 15 computers and would prefer something subscription free. Is there some FW appliances that would do this for a cheap price?

NeilSanner

A router that does NAT, and I think that's all that the 784 does, is find for a small business that practices safe computing methods and is not running any public accessible servers/services.

If you make sure to secure your computers, use FireFox and patch the computers for Windows XP and Office updates (assuming your using XP and Office), and you check the router logs frequently, you should be secure enough.

Just make sure that you run a Quality Antivirus program on EVERY machine, and that you FULLY UPDATE/PATCH all Windows OS and Applications.

If you can get a Linksys unit instead, there is a free program called WallWatcher that you can run on a workstation that will display your logs (internet) showing all inbound and outbound traffic source/destination as a means to tell you want's happening with your internet connection.

"neilSanner" wrote in news:1115677267.026117.271170 @o13g2000cwo.googlegroups.com:

No you don't need a $2,000 FW appliance. However, you don't need a cheap NAT router (no FW) that's wireless either that can be compromised either.

They have affordable low-end FW appliances that have a (true) FW.

Home many users are you talking about?

I got a low-end FW appliance for around $250 that supports 10 users. They have wireless ones too but I would not get one for a business.

You'll want something like what's in the link for *what does a FW do?* that's meets the specs in the link and not a NAT router that's wireless and for home usage that doesn't meet the specs.

formatting link
formatting link
Duane :)

Reasonable advice on the surface, however the OP should carefully consider whether or not his small business is 'secure enough' behind a NAT router - which depends entirely on the nature of the business, and the extent to which all internal users are trusted to consistently employ safe computing practices.

One must consider all data stored on internal systems, and the potential impact of any breach of confidentiality, integrity, or availability of this data to the business. Such impacts may include legal, regulatory, or commercial issues.

IMHO it is irresponsible to recommend a security solution when one has no knowledge of the assets requiring protection.

Triffid

"neilSanner" wrote in news:1115680805.571655.196800 @z14g2000cwz.googlegroups.com:

Once you buy a FW appliance, you don't have to renew the subscription and continuously update the firmware. Most likely, you'll not need to update the firmware. My subscription expired last month and I will not update the firmware unless I am forced to do so for some security issue that the firmware on the device couldn't handle and I was concerned about it. And I don't see that happening.

I use a low-end WatchGuard but there are others too like Sonicwall, Netscreen, Snapgear.

There was a post made to me about WG(s) here recently where you could purchase a WG for a good price -- find my name and you'll find the link.

I cannot find the post out here in the NG and maybe someone will assist with that info again.

You my have to up the number of users that the firmware can support as mine will only support 10 users -- that cost is a little more.

You can also go out to CDW.com and look at devices there too for all major brands -- the price is another story. ;-)

Duane :)

The site I mentioned - and they are authorised resellers for Watchguard (as well as Sonicwall but at another site) - is

formatting link
Their Sonicwall site is
formatting link

Apparently very good reviews of these people on the watchguard forums (available only to subscribers) and prices close to the cheapest (although not the very cheapest).

By the way, for those who would like to browse around the private watchguard forums and see what is going on with customer queries etc but have not purchased a watchguard yet you can read the forums at this Swiss archive (which is very much up-to-date and is a mirror of some sort) you can look here:

formatting link
I assume that the talked about "mailing list" is indeed the same as the Watchguard forums I mentioned above as I see Watchguard employees posting there. Unfortunately, the forum layout is not the best and there is not a proper tree view.

Peter

Peter

It seems to only be a small slice of the forums as none of my posts to the private boards are on it, and I've been posting there for almost 5 years.

Peterg wrote in news: snipped-for-privacy@news.telus.net:

Hey thank you.

I book marked them this time.

Duane :)

I work at a small business and we use a DI-614 IIRC. It was there when I started and we have had no problems with it. However, I personally think a dedicated linux firewall like ipcop (ipcop.org) is a much better solution. It does web filtering with squid, has snort intrusion detection, lots of pretty graphs and stuff, it's actively maintained, and it's free. For a small network pretty much any older computer with two network cards will work fine. $2000 is definitely overkill for your application.

That's seems very promising. I'm gonna have a serious look at this.

Watchguard

This would be not so bad hey?: Firebox® SOHO 6 for $279.95 + Upgrade from 10 to 25-User License for $158.95 = $438.90.

I also looked at the D-Link DFL-200 (456$), which as Intrusion Detection/Prevention System (IDS/IDP). It also includes VPN at no extra charges (no charge to activate it and no Mobile User VPN Tunnels upgrade fees). Could it be a plausible solution for a small business?

Definition of IDS: ftp://ftp.dlink.com/Gateway/dfl200/Manual/DFL200_manual_101.pdf Example of an IDS signature: ftp://ftp.dlink.com/Gateway/dfl700/IDS_Signature/idssigs-20040503.txt

Ah, but you get what you pay for and what you supply the specifics for on Usenet.

Most people that has sensitive personal data or that have to be HIPAA compliant don't ask about NAT Routers, they already understand the impact and that a real firewall is needed.

While it may be irresponsible to you, it's irresponsible for them not to ask and not to get any feedback.

Cool. My D-Link DI-604 just died (and out of warranty) so I was looking for a replacement for a home NAT router. Looks like a Linksys will be the replacement (any opinions regarding Netgear?). Is the info from the router's log anymore useful than those in the software firewall's log (other than aggregating the logs from multiple hosts since all are going through the router)?

Hi there,

I don't quite know the firewall stuff, and am still learning. Actually, I wanted to post a similar question to yours ;-)

From my experience, never buy things from D-Link. I'm running a computer shop and sold many ADSL modem/router sort of things. Among what I sold, D-Link is the worst, absolutely. Note: this is not what I said, it's from my customers. I really hate D-Link!

Cheers,

Lei

"neilSanner" wrote in news: snipped-for-privacy@f14g2000cwb.googlegroups.com:

That means you learn, understand and implement it and maintain it. Do you have the time for all of that?

It's a plug it up and go device with very little configuation on your part.

It too is a plug it up and go device.

It depends on your needs. If your small business had branch offices that needed a VPN connection to your main office or you hand workers that were working from home needing a VPN connection, then by all means. If you don't have the situation, then why do you need it?

If you had some huge corporate network and the router was part of a total FW solution, then why would you need it? Or if you hand a Webserver and SQL Server on the network, then I could see justication. If you don't have such a set-up, then why do you need it

If you were looking at a cheap NAT router, then I would suggest you go with a plug it up and go device and be done with it and make things ease on yourself.

Duane :)

Very good advise - to bad we never seem to get people posting their actual requirements in here. It would like getting candy for a baby if people asking for help actually posted specifics of the needs.

I've use enough of the different ones to say I've use them All, but I keep using Linksys BEFSR41, BEFVP41 and some BEFSX41 units - If I need wireless I purchase and Access Point, not a router with wireless built into it.

Look at Wallwatcher.com - it's a great product and provides all the logging and summary info you could ever need.

Nobody can give you a serious advice unless he has detailed information about

- existing security measures

- threats you want to be protected from

- value of your data

- network infrastructure

- user behaivior

- etc.

If total costs of a compromise are higher than the costs of the firewall (whatever that is) than the particular firewall makes sense economically. Any firewall that costs more than a compromise costs does not make sense economically.

Apart from that even the most expensive devices can be misconfigured and therefore can be useless. If you want to spend money, spend it on someone with knowledge and experience, such a person will find a solution. If the first word he says, is 'You need $PRODUCT from $VENDOR', sack him immediately. Instead ask him to discuss the pros ans cons of several solutions. If you are uncertain, ask for a second (or third) opinion.

Wolfgang

Thanks.

Unfortunately most people who ask here lack the knowledge to describe their security needs. They are afraid of abstract dangers and want to be protected but once you try to get more information about what they fear, they are often unable to explain their fears. Their knowledge comes from what they see on TV or read in magazines, which often deal with security issues on a rather low level. Nevertheless security remains a complex matter that ranges from physical access to network cables and sockets up to exotic buffer overflows in a service implementation that might (only) be exploited from remote under quite exotic conditions.

There are dangers on every layer of the network model and to overcome them measures on every layer have to be taken starting at the lowest layer. Everybody who wants to spend a lot of money of an expensive firewall device but has taken no measures to restrict physical access to machines, network cables and sockets should better make a gift to any welfare organisation and by doing that he has probably done more good with that money than spending it on the firewall device.

Wolfgang

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required