Should You Fire Your Firewall?
Gsurface writes "A lengthy article over at Flexbeta.net focuses on firewall applications and how well they perform as far as securing your system. Four typical firewall applications were tested including two routers, one being the Cisco 831 SOHO, which performed rather well. In total, nine security test were conducted to measure how well each firewall performed."
Very interesting, although I'ven never been much for hardware firewalls. I grab an old machine, load it up with Slackware 9.1, and custom-configure the netfilter/iptables rules. I's a lot more versitile, and it's not just a firewall. It can be expanded to run every server known to man, such as ssh for remote control, or FreeS/WAN, for VPN.
Any review of security/firewalls using Gibson's crappy analysis tools is beyond flawed. I would take all of this review with a grain or two of salt.
Yes, I am an agent of Satan, but my duties are largely ceremonial.
But the port it shows as closed is 113 which is sometimes needed to authenticate to ftp or web sites. The authors of the review are assuming that the best firewall stealths absolutely everything. But if a product completely protects your system why wouldn't that be good enough? Same for ZoneAlarm4 not stealthing several ports under Advanced Port Scanning.
I like the way they bring up outbound filtering though. Most "personal" firewalls don't do anything with this.
Does this really belong in the Your Rights Online section?
I decided to try some of these tests myself. When testing using TooLeaky, I got a notification that it sent the information to GRC.com and recieved information from GRC.com, even when I disabled my internet connection.
Sounds like BS to me.
This is just one more case where an excellent area of inquiry is ruined by the wording of a Slashdot article, and by people trying to show how much they know without saying anything that could actually be used by someone else.
The article at Flexbeta should not be worded, "An In-depth Look at Firewalls", it should be "An In-depth Look at Small System Firewalls". Most single computers or small LANs have no servers.
The parent post is considering an important issue for systems of 100 users. Systems that large are far out of the scope of the Flexbeta article.
We need two Slashdot articles on firewalls, one for small systems, and one for more complex LANS.
The Flexbeta article considered only Linksys (now owned by Cisco) and D-Link small system hardware firewalls. It did not consider Airlink Plus and Netgear.
I got burned with poor technical support from Cisco. Also, Cisco stopped supporting its 675 router. I don't want to be involved with Cisco again, so Linksys is out, especially because of the confused Linksys web site. Cisco has an enormous conflict of interest. If Linksys sells good firewalls, it will mean Cisco sells fewer.
So, which is the better hardware firewall, D-Link DI-604, or the Netgear RP614?