Adam Maas wrote:
Ryan K. Brooks wrote:
Don Williams wrote:
The only way to be as safe (as its possible to be now) is to have a
hardware firewall. Many of the wireless 'modems' are also firewalls.
Its just a matter of configuration. I have a pretty good one
'Speedstream 5667'. I have disabled the Windows software firewall
software because its just a bloody nuisance.
No home user actually has a hardware firewall. These devices
(linksys, etc.) are just small computers running OS'es and firewall
software with their own set of problems.
It may help to abstract the firewall from the host computer, but it's
just more software in a black box...
-Ryan
Ryan,
That describes even the highest-end firewall, many of which are
actually running on some Unix variant (Linksys uses Linux, Checkpoint
runs on Solaris, Linux or FreeBSD). A hardware firewall is nothing
more than a piece of hardware dedicated to firewalling (And usually
basic routing as well) and those little consumer boxes are hardware
firewalls, even if they aren't as powerful or secure as a PIX or
Checkpoint. But if they're doing NAT, they're secure enough for most use.
Nope, a hardware firewall filters in silicon, ala high-end Cisco or Juniper.