Pelican Parts
Parts Catalog Accessories Catalog How To Articles Tech Forums
Call Pelican Parts at 888-280-7799
Shopping Cart Cart | Project List | Order Status | Help



Go Back   Pelican Parts Forums > Miscellaneous and Off Topic Forums > Off Topic Discussions


Reply
 
LinkBack Thread Tools Rate Thread
Author
Thread Post New Thread    Reply
Registered
Which Firewall to use? How to configure??

Hi all,


I have cable access to the internet at home. Goes from the modem to a Dlink DI-614+ (wireless accesspoint/router). I want to set up a firewall and from what I understand it's best to do it at the router/access point. I'd like to protect all PCs downstream of the Dlink unit and avoid overhead on each individual PC if possible.

But how do I configure? The manual is extremely vague and the website is just as bad. I understand how firewalls work from a theoretical standpoint but I'm stumped by how to configure this thing.

Anyone been through this? Any advice appreiciated.

__________________
Warren & Ron, may you rest in Peace.
Old 01-12-2005, 12:24 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #1 (permalink)
Registered
 
tabascobobcat's Avatar
 
Join Date: Jun 2000
Location: Columbus, Ohio
Posts: 747
Garage
I am using Easy Armour provided free from Road Runner.
Seems fine. No issues.
I un-installed the Norton's 2001 and many of my conflicts went away with it.
__________________
2005 Acura 3.2 TL 148,000 miles
1988 911 Cabrio 104,xxx miles
1965 Honda Super Cub 50 1442 miles
2008 Honda Odyssey 105,000 miles
GruppeB #0202
Old 01-12-2005, 12:44 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #2 (permalink)
Moderator
 
Bill Verburg's Avatar
 
Join Date: Dec 2000
Posts: 26,402
Garage
I agree, the Norton firewalls have way too many issues, Easy Armour seems to be the way to go, also most routers have a hardware firewall that works well.
__________________
Bill Verburg
'76 Carrera 3.6RS(nee C3/hotrod), '95 993RS/CS(clone)
| Pelican Home |Rennlist Wheels |Rennlist Brakes |
Old 01-12-2005, 01:03 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #3 (permalink)
Too big to fail
 
widebody911's Avatar
 
Join Date: Jan 2002
Location: Carmichael, CA
Posts: 33,894
Garage
Send a message via AIM to widebody911 Send a message via Yahoo to widebody911
I use ZoneAlarm and MAC filtering with my DSL router.
__________________
"You go to the track with the Porsche you have, not the Porsche you wish you had."
'03 E46 M3
'57 356A
Various VWs
Old 01-12-2005, 01:10 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #4 (permalink)
Feelin' Solexy
 
Tishabet's Avatar
 
Join Date: Oct 2003
Location: WA
Posts: 3,788
Zonealarm pro, I love it
__________________
Grant
In the stable: 1938 Buick Special model 41, 1963 Solex 2200, 1973 Vespa Primavera 125, 1974 Vespa Rally 200, 1986 VW Vanagon Syncro Westfalia, 1989 VW Doka Tristar, 2011 Pursuit 315 OS, 2022 Tesla Y
Gone but not forgotten: 1973 VW Beetle, 1989 Porsche 944, 2008 R56 Mini Cooper S
Old 01-12-2005, 02:04 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #5 (permalink)
Registered
 
911S Targa's Avatar
 
Join Date: Aug 2004
Location: Sin City
Posts: 991
Garage
I run a linksys wireless router, and use the firewall on that, which sets up its self, then I also use the Windows XP Pro's firewall.
__________________
Bill
MID9 #4

if i cant play with it ,,i dont want to own it
Old 01-12-2005, 02:10 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #6 (permalink)
 
Registered
 
id10t's Avatar
 
Join Date: Mar 2003
Posts: 10,322
Your DLink router/ap should do it for you, if even thru just using NAT. As long as you don't open any ports to forward services to your LAN, you'll be fine. Of course, you are still vulnerable to viruses, etc. from user action or an application exploit (like IE has happen all the time), but the worms like Blaster, Sasser, etc. won't be able to get in.
__________________
“IN MY EXPERIENCE, SUSAN, WITHIN THEIR HEADS TOO MANY HUMANS SPEND A LOT OF TIME IN THE MIDDLE OF WARS THAT HAPPENED CENTURIES AGO.”
Old 01-12-2005, 03:33 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #7 (permalink)
Registered
 
David's Avatar
 
Join Date: Apr 2002
Location: Houston (Clearlake), TX
Posts: 11,215
Garage
A little off the subject, but I just had another D-Link DI-624 wireless router go bad. Anyone else have trouble with these?
__________________
2014 Cayman S (track rat w/GT4 suspension)
1979 930 (475 rwhp at 0.95 bar)
Old 01-12-2005, 04:22 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #8 (permalink)
Registered
 
mikester's Avatar
 
Join Date: Mar 2002
Location: My House
Posts: 5,345
Send a message via AIM to mikester
Okay - here's my suggestions...price not being a factor at all.

If your OS is Windows XP I suggest you use the firewall that comes with it OR Zone Alarm. Zone Alarm is a good product but requires some configuration which takes time and patients. Offloading the Firewall function to a hardware device is ideal but even if you do this with a dedicated firewall my suggestion would be to still run the XP firewall. If you need file sharing in your local network the XP firewall can accommodate this need.

An extremely good hardware firewall is made by Cisco, it’s the PIX 501 – I have one myself and I love it but it requires some expertise to configure and it is a bit on the pricey side even on eBay. If you know someone who is a Cisco reseller then you might be able to get one for ~$400 unless they get super discounts. The next stop on the firewall lineup would be one of Linksys (owned by Cisco) products that offers and integrated firewall. This is the most realistic solution and it really doesn’t need to be a Linksys product as their competitors do a good job for the home market as well. Belkin, D-Link, etc make decent products just stay away from the no name brands.

Let me know if you have any questions.
__________________
-The Mikester

I heart Boobies
Old 01-12-2005, 05:09 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #9 (permalink)
Registered
 
id10t's Avatar
 
Join Date: Mar 2003
Posts: 10,322
Of course, if you want to get really serious and geeky about it, just use a old PC (anything Pentium class, 32mb or more RAM) and run either Linux or BSD on it and use either iptables (linux) or pf (bsd). Of course, this will take some learning to get it configured right, but there are lots of dedicated firewall Linux distributions like smoothwall that make it really easy to do.
__________________
“IN MY EXPERIENCE, SUSAN, WITHIN THEIR HEADS TOO MANY HUMANS SPEND A LOT OF TIME IN THE MIDDLE OF WARS THAT HAPPENED CENTURIES AGO.”
Old 01-13-2005, 05:24 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #10 (permalink)
Registered
Thanks guys. I will attemt to allow the DLink to do an auto config.

Basically, traffic is allowed to flow out but is limited coming in through one or two ports...correct?
__________________
Warren & Ron, may you rest in Peace.
Old 01-13-2005, 06:07 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #11 (permalink)
Registered
 
id10t's Avatar
 
Join Date: Mar 2003
Posts: 10,322
Correct. You don't even want incoming unless you are offering a service or doing stuff like p2p apps..
__________________
“IN MY EXPERIENCE, SUSAN, WITHIN THEIR HEADS TOO MANY HUMANS SPEND A LOT OF TIME IN THE MIDDLE OF WARS THAT HAPPENED CENTURIES AGO.”
Old 01-13-2005, 06:28 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #12 (permalink)
Registered
What about viewing sites, downloading software or watching racing clips? That's incoming isn't it?
__________________
Warren & Ron, may you rest in Peace.
Old 01-13-2005, 06:57 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #13 (permalink)
Registered
 
Join Date: Sep 2002
Posts: 3,580
Quote:
Originally posted by RickM
What about viewing sites, downloading software or watching racing clips? That's incoming isn't it?
Anything that you've requested by clicking a link, etc, is let through, because you started the session.

I'm a big proponent of a hardware firewall at your broadband (DSL/Cable) connection PLUS a software product such as XP's firewall or Zonealarm on each box on your LAN (home network in this case). Zonealarm is nice because it monitors outgoing connections and asks if you want to allow them, until it learns what everything is. So if you have a Trojan on your PC, and it's trying to send something out, ZA will ask if that's OK, and you'll discover the Trojan.

One of my staff at work manages a Symantec firewall with about 250 clients, and some things do get through the first "layer" of defense sometimes. Sometimes it's user error, sometimes misconfiguration, sometimes a new exploit that is taking advantage of newly found weaknesses. It never hurts to have a software firewall picking up the slack.

Whatever you do, try going to www.spinrite.com after you are set up. They have a "port scanner" that will check out your firewall defenses and let you know (in somewhat over-the-top language) if you are letting bad stuff in.

Good luck!
__________________
993
Old 01-13-2005, 07:27 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #14 (permalink)
Registered
Great info....thanks!

__________________
Warren & Ron, may you rest in Peace.
Old 01-13-2005, 08:06 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #15 (permalink)
Reply


 


All times are GMT -8. The time now is 12:27 AM.


 
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0
Copyright 2025 Pelican Parts, LLC - Posts may be archived for display on the Pelican Parts Website -    DMCA Registered Agent Contact Page
 

DTO Garage Plus vBulletin Plugins by Drive Thru Online, Inc.