Most Popular Hardware Firewalls?

Feb 25, 2006 67 Replies

No, it looks at the approved list, and doesn't even allow the request outbound, it returns the approved result - either the error or the site address.

Very, just not something many home users are willing to invest in. I have a WatchGuard Firebox 1000 in my home, protecting my family and network.

And this solution is based on your saying you can tunnel, which has nothing to do with home/business, either you can block it or your cant - and I say it's easy to block.

Prove to me that this would work against Netscreen, WatchGuard, CheckPoint-1, etc.... Nothing has been proven or disproved with regard to that.

Still the question: Why is it implemented at the firewall level rather than at the DNS server level?

Whenever you're not stoned any more, you might rethink how practical whitelisting is for home users. Hint: not at all

This has already been shown various times, including DJBs latest work on timing fingerprinting and remote key extraction.

Why would you want to trust the OS to protect itself - since most of the servers are running Windows based OS (the ones I assume we're talking about), there is no reason to trust Windows to protect itself.

It's only impractical if you don't feel the need for it.

Show me where it applies to the Firewall Appliance (and we're not talking about a NAT Router).

This has nothing to do with the OS, it's about the DNS server configuration.

What exactly is your complaint about the WinNT kernel ACLs? Works quite well so far.

It's a good idea to not post on the Usenet when being stoned. :-)

Let me guess: You didn't even take on little move to enter "firewall timing attack" or alike to Google?

Wrong, it has everything to do with protecting the OS, which the DNS service runs on - there is no reason to directly expose it when it can be protected by the firewall first.

I've been using Windows servers attached to the Net since NT 4, and running IIS on many of them for public sites, never had one compromised while implementing standard security practices, and that includes locking it down completely and a firewall layer outside of the OS. Why should I trust something that has holes and exploits over what I know works even if the OS has holes/exploits.

It's a good idea to not resort to insults on Usenet when you're tring to make a point - it shows that you've lost your position and have nothing left to back it up.

You followed VB, who we all know is missing a few bolts when it comes to security, and you can't back it up? Why should I have to disprove something you can't prove?

If if there wasn't a DNS service on that machine, would it meant it doesn't need to be protected?

And how is that related to the configuration of the DNS service anyway?

Filtering DNS requests is not a matter of exposure. Neither is it a pratical consideration.

This is about exactly how firewalling does not work. The firewall is the secondary redundant layer, not the clients or the network.

Sorry, but it seems like you have a big lack of reality - whitelisting is impractical for home users, whether you feel an unfounded need for it or not.

Wouldn't "I have no arguments" be a shorter expression of your point?

Once again: You're unable to inform yourself. Even Google shows a lot of very good references to the topic, but it seems like that just the threads in this ng containing "benchmark" and "performance" don't get you a clue about what timing attacks are. Covert channels don't exist in your reality and whitelisting and throwing around with arguments named as facts solves every problem. Go figure.

Uh, this thread went off in an odd direction. I've looked at the reviews of such inexpensive units as the D-Link DI604 and the Linksys BEFXX401 and seen plenty of unhappy customers. Plenty of bitching about buggy firmware and disconnects. What hardware firewalls are people most happy with? Thanks!

Sometimes I think it's all about who can piss the longest and furthest...

Anyway, I'm hoping the Fortigate 60 turns out to be good. I just bought

2 of them, for HA, based on price and feature set. I've not yet had a chance to test them, however...

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required