Tom's Hardware Forums » General Networking » Firewall » Firewall question.
 

Firewall question.




Word :   Username :  
 
Bottom
Author
 Thread : Firewall question.
 
Bob
Profile: stranger
More Information

Archived from groups: comp.security.firewalls (More info?)

 

Hello,
I have a question for you all please.

I have been running the XP firewall, but now have a firewall made by
Sygate. Do I need to turn off the one in XP, or is it OK to run them both
for the added protection?
I have heard both, but I thought that a few of you guy who seem to really
know your stuff in here might be able to give me the correct answer.

Thanks,
Bob

Related Product

Register or log in to remove.

More Information

Archived from groups: comp.security.firewalls (More info?)

 

"Bob" <ace-62@earthlinkNOSPAM.net> wrote in news:CA%kc.1527$a47.1023
@newsread3.news.atl.earthlink.net:

> Hello,
> I have a question for you all please.
>
> I have been running the XP firewall, but now have a firewall made by
> Sygate. Do I need to turn off the one in XP, or is it OK to run them
both
> for the added protection?
> I have heard both, but I thought that a few of you guy who seem to
really
> know your stuff in here might be able to give me the correct answer.
>
> Thanks,
> Bob
>
>
>

If you want to run two, then run one that has many of the FW like
features and does more than the XP ICF that's on the O/S. Malware can
take down any third party host based FW easily, but it's hard to take
down IPsec, since it's integrated with the O/S.

In addition to this, XP's FW upon the release of SP 2 will have
application control that will bring XP's FW on par with third party host
based FW(s).

Currently, IPsec will get to the TCP/IP connection first at boot and XP's
SP 2 FW will also get to the TCP/IP connection at boot.

At boot is a vulnerable situation for a machine with a third party FW
solution installed, since malware will beat any of them to the TCP/IP
connection and be done by the time any of them can get there and stop it.

http://www.petri.co.il/block_ping_ [...] _ipsec.htm
http://www.analogx.com/contents/articles/ipsec.htm

All you have to do is implement the AnalogX Secpol file and you're
covered. The POP3, HTTP etc, etc for the *client* are already configured.

You may want to look at *Protecting against Denial of Service Attacks*
being discussed in the link.

http://www.uksecurityonline.com/husdg/windowsxp.php

On the other hand, you may want to get a cheap NAT router and use Sygate
and IPsec behind it to supplement, like I do with the NAT router BlackIce
and IPsec on all machines.

A cheap NAT router cost as much as you have paid for Sygate, if not the
free one, because a NAT router stops everything in front of the machine
and the O/S and the FW will not react -- the true *stealth* part in a *I
am stealth* statement. :)

http://www.homenethelp.com/web/explain/about-NAT.asp

Duane :)

More Information

Archived from groups: comp.security.firewalls (More info?)

 

"Bob" <ace-62@earthlinkNOSPAM.net> wrote in news:CA%kc.1527$a47.1023
@newsread3.news.atl.earthlink.net:

> Hello,
> I have a question for you all please.
>
> I have been running the XP firewall, but now have a firewall made by
> Sygate. Do I need to turn off the one in XP, or is it OK to run them
both
> for the added protection?
> I have heard both, but I thought that a few of you guy who seem to
really
> know your stuff in here might be able to give me the correct answer.

My 2 cents:

While some software firewalls (such as Norton) are stated by the company
as being able to run concurrently with the WinXP firewall, I've seen
somewhere (I think the Sygate site or the documentation), that Sygate is
not to be run with another software firewall.

Although I ran both Norton and the XP firewall concurrently for a long
time (until I got my router) and had no apparent problem from doing so, I
don't know if it really serves a useful purpose - the only one I can
think of is if the main firewall (the non-XP) somehow becomes
deactivated, there is still hopefully incoming protection.

--
Tom McCune
My PGP Page & FAQ: http://www.McCune.cc/PGP.htm


Go to:
 
  Tom's Hardware Forums » General Networking » Firewall » Firewall question.

Google Ads
Ad
News

Microsoft readies two-way firewall for Vista

Published on January 26, 2006

Microsoft is readying a new, highly configurable firewall for its upcoming Windows Vista operating system that is designed to give administrators much greater control over which applications are allowed to run on the systems they manage. Read more

Gigabyte intros SLI mainboard

Published on November 22, 2004

Gigabyte follows Asus as one of the first manufacturers to offer a SLI-capable mainboard to run two graphics cards. Read more

One in four PC users hit by phishing attacks, says AOL

Published on December 07, 2005

AOL today published the results of a sponsored study that found that 23 percent of US users are targeted in phishing attacks, with 70 percent recipients of scam emails believing they were from legitimate companies. Read more

Kaspersky adds firewall, anti-spam features

Published on May 15, 2006

On Monday, Kaspersky Lab unveiled the latest versions of its anti-virus and Internet security products aimed for the consumer and small business markets. Read more

Latest Reviews & Articles

Part 4: Avivo HD vs. PureVideo HD

Published on September 29, 2008

The 780G chipset/Radeon HD 3200 and the MCP78S chipset/GeForce 8200 provide the first integrated graphics solutions that can accelerate Blu-ray playback. We dig deep into how well they work with high-quality Blu-ray 1080p video playback. Read more

Four GeForce 9600 GT Cards Compared

Published on September 26, 2008

Manufacturers really love the first Geforce 9. The graphic chip is fast, the cards are inexpensive, and some retailers offer more than ten variations. Read more

Maxtor's Shared Storage Does NAS At Home

Published on September 25, 2008

What do you do with all the data you collect at home? Network attached storage is the solution. We test Maxtor's Shared Storage II and find that it is also suitable for use in small businesses. Read more

SLI & Centrino 2: Gaming Laptops Battle

Published on September 24, 2008

Take four gaming laptops. Arm two of them with SLI and make the others Centrino 2-compatible. You're looking at a high-end collection of the latest mobile technology battling it out for benchmark supremacy and your hard-earned dollars. Read more