No, I think it is a problem of complexity. A PFW wants to be a host-based packet filter, application traffic filter, intrusion detection system, privacy filter, malware detecter and much more. A HBPF is something very important and should work reliably. Mixing it with much other stuff just increases the dangers of errors. Real intrusion detections systems are usually big expensive dedicated boxes with a lot of CPU power. Content filter and application firewalls are also extremely CPU intensive devices. A PFW wants to do all that (basically checking the complete content of your internet traffic) while it is running on the very computer itself and has to share resources with the rest of your applications.
Gerald
Didn't find your answer? Ask the community — no account required.
G
Gerald Vogt
This is still ancient in computer time. Microsoft Office 97 also runs much faster on a new computer than Office 2003. Word 2 run very nicely on DOS machines. But if you keep feeding the cow filling it up with millions of features, the cow will get fat and slow... Running a 5 year old software, even if there have been some updates two or three years ago to fix some important problems probably, do not make it much younger. Again: try using the most current version of Kerio on your computer.
O.K. As I said, lucky you.
Seems as if all that's left for you is to try to piss other people off. All you have is the experience of one old computer that you have. This experience leads you to the conclusion that all application firewalls work great and without problems. I know how to configure NIS, but noone can configure it "properly" anymore because it is just much too complex. Even Symantec support is unable to do that at times...
Gerald
B
bassbag
No.....Your the one that said you had problems wih NIS and spouted claptrap that application firewalls use 75% cpu consumption.Your the one who couldnt understand NIS annd its application rules or whether it was a "zillion" other things.Your the one who presumes everything (you seem to know my experience ,what computers i have etc etc etc, and that thinks hes an expert. But from your postings you seem to me like an arrogant self opinionated man who bases his opinions on his own failings.If ive pissed you off then good (it must hurt when your wrong but too arrogant to admit it).If ive pissed others off then i apologise. me
G
Gerald Vogt
I did not say I had problems with NIS. I said that many people have problems with NIS. That's an observation. I did use NIS for a while and it got slower with each year.
You don't know anything.
I don't know your experience. All I have is what you write. You are always writing about _your_ experience on _your_ old computer with Win98. That is all you are writing about. As long as you don't write more about your experience all I can do is assume that what you write is actually all you know. I have seen many computers from many people with various problems. I have also read from many reports and discussions in Newsgroups and other forums. Based on that I have my experience. I don't presume anything except what you write. You were the one who wrote: you have a W98 with PFW with little CPU usage and concluded that obviously all PFWs on all computers with any OS and any version run with little CPU usage.
I just wrote my opinion and what I learned from many experiences with various computers. You just wrote from your one computer which is - sorry - totally unrelevent. If 75% of the people have problems with something and you have not, than lucky you, but it still indicates a general problem with that something.
Gerald
B
bassbag
I replied to the original poster with a view and my opinion.You on the other hand replied to MY post trying to bolster your warped ideas.I guess your newreader is easier to understand than the firewalls ,so do me a favour and go find the killfile function. me
R
rrweis
Firewall
You should try the leak test at Gibson Ranch to see if outbound is open, me, I used winxp firewall latest and had several problems, switched to a low cost firewall and everything has settled down, zone alarm keeps saying that remote computers have tried to connect , ect so many times , plus many have been serious, with my new firewall, there has been zero attempts,,,
G
Gerald Vogt
Sorry, but you failed the leak test. I have no problems with it and I am only running XP SP2. Your fault is that you download an executable from some source, execute it and does not accept that it may talk to the internet.
What low cost firewall? Do you mean a low cost personal firewall or a hardware "firewall" aka NAT router? The latter does not give you fake outbound protection either so I suppose it must be the first. If it is a PFW and you assume "everything has settled down" you are extremely vulnerable because you rely on the PFW and its security functions and in particular the outbound protection which can be easily circumvented. In other words, if you run some rogue application that you have started and your PFW does not report any blocks it means either that the application is not communicating at the moment, or the application is communicating through some undetected tunnel or the application already reconfigured the PFW to let its own traffic through. If you rely on the outbound protection of your PFW and assume as long as there are not messages I'm safe and also if there are messages and I block them I prevented some application from sending _any_ messages that you are wrong and thus vulnerable.
The bottom line is always: to not run malware because bascially all malware must be started first by the user. If it does run automatically than in almost all cases it is either that some security updates are missing or that the system is badly configured (e.g. accept any unsigned installation etc.)
This is not correct. There are still many remote computers trying to connect. A firewall's job is to block those. The question is whether there is any use telling the user about a blocked connection attempt. If you are in a dial-up/dsl IP range I would not wonder if you get a connection attempt per minute (it depends on which new virus/worm is around and how active they are). The firewall blocks them. That is what it is supposed to do. No need to report this to the user. In particular no use to report to users connection attempts to ports where actually noone is listening to as there is nothing to protect. PFWs like to report this because then the user gets the impression how important the PFW is and what a great job it does and that without the PFW the user would be victimized within minutes although many of those attempt would not work with or without firewall so it is absurd to see those messages on non-active ports where a firewall actually has nothing to do in the first place.
Gerald
I
Ian Pollard
I tried it and found one hole. I have now re-downloaded an earlier version of Sygate Personal Firewall, rerun the Gibson tests and everything is working just fine. Apparently the latest version of SPF is where the trouble lies.
Ian
Join the Discussion
Have something to add? Share your thoughts — no account required.
Didn't find your answer?
Ask the community — no account required
Report Content
You are reporting this content to the moderators. They will look at it
ASAP.