Security: Firewalls

If you spend a lot of time on the internet and you areThey have the following disadvantages:
not behind afirewall, then you are living on borrowed- They tend to be expensive, although if you have a
time. Putting some protectionbetween you and thenumber of machines toprotect it can cost less to
internet is probably the third most important thingpurchase one hardware firewall than a number
thatyou can do (after getting virus checking softwareofcopies of a software product.
and performing regularbackups).- Since they do not run on your computer, they can be
The diagram to the left shows an unprotected systemchallenging toconfigure.
using a DSL modem. Asyou can see, someone on theFirewall mixture - In my mind, the best protection is a
internet can attach the computer system easilyas thecombination of bothhardware and software firewalls.
DSL modem provides no protection (some DSLThis is the ideal, since both havedifferent advantages
modems have built-infirewalls). An attacker can getand disadvantages. Personally, I use a
through any type of modem - DSL, cable, 56K,SonicWallhardware firewall combined with ZoneAlarm
28.8 or whatever. If the device gets you on thePro, which is installed on my
internet, you arevulnerable.Windows 2000 Professional system. The SonicWall
For those with a DSL, cable modem or otherprotects my home networksince it sits between the
"always-on" connection, you MUSTget a firewall. Thishub and the DSL modem, and ZoneAlarm Pro
is critical, as your machine is always live and itofferssome additional protection for each system.
mostlikely has a fixed IP address. This makes it easierTesting Your Firewall - To test your firewall, surf to
for your system to berequest a probe. You will be given a very good report
"found" and attacked.of exactly whatissues were found and what to do
What a personal firewall does is isolate your computerabout them. Once the probe is finishedseveral
from the rest of theinternet. It does this by inspectingexcellent personal firewall products are recommended.
each packet of data to determine if itit should beMy personalfavorite is ZoneAlarm Pro, primarily
allowed to get to (and in some cases from yourbecause it's protection is excellentand it is trivial to use.
machine.) Thebest protection completely hides yourSome Firewalls - A selection of personal firewalls is
computer - this is called stealthmode.listed below.
You have the option of installing a software firewall or- ZoneAlarm Pro - By far the best software firewall
a hardwarefirewall.available. ZoneAlarmoffers protection from both
Software Firewall - A software firewall runs on yourincoming connections and outgoing connections.
computer system in thebackground. It intercepts eachIt is also extremely easy to configure, has low system
network request and determines if the requestis validimpact and is veryinexpensive (a free version is also
or not. Software firewalls offer the followingavailable).
advantages:- Norton Internet Security 2001 (which was the
- They are generally very inexpensiveAtGuard product from WRQuntil a few months ago).
- They are very easy to configureNorton is a reasonable firewall, although it doeshave
They have the following disadvantages:some vulnerabilities. It offers weak protection from
- Since they run on your computer they requireoutgoingconnections and is somewhat difficult to
resources (CPU, memory anddisk space) from yourconfigure if you want it to operatedifferently from the
system.default.
- They can introduce incompatibilities into your- BlackIce - A good choice in firewalls. Much easier
operating system.than Norton toconfigure, but with the same
- You must install exactly the correct version for yourvulnerabilities.
operating system.What I've done on my system is:
- You must purchase one copy for each system on- Used a SonicWall hardware firewall to protect my
your home network.entire home network.
Hardware Firewall - A hardware firewall is generally a- Installed ZoneAlarm Pro on ach system to provide
small box which sitsbetween your computer and youradditional safety
modem. In general, hardware firewalls havethe- And installed Norton Internet Security for it's privacy
following advantages:protection.
- They tend to provide more complete protection thanDue to the rapidly changing nature of the internet, it's
software firewallsvery important tobe continually monitoring security
- A hardware firewall can protect more than oneissues. You may purchase the perfectpersonal firewall
system at a timetoday, only to find out in six months that it's
- They do not effect system performance since theybeenhacked to pieces. So be sure to be looking
do not run on yoursystem.around, and be ready to get anewer and better
- They are independent of your operating system andproduct quickly. This is not one of those issues where
applications.youcan scrimp and save. Your system is at risk.