|
Search
|
||||||
Firewall config confusionSystem Security File System security, OS Security, software firewalls and any other type of security topics reside here. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
||||
|
||||
|
Firewall config confusion
I prefer to use at least some kind of firewall. For a while, I've been relying on my router's firewall, with the addition of Windows Firewall... However I've run into some issues that are forcing me to find an alternative way, and I am having trouble with it.
Essentially, I have trouble configuring a firewall. I am using an application which requires a wide range of open ports for communication across the Internet. Wide as in 50000-65535. My router's firewall does not allow opening a range of ports, which renders the application unusable. So, I "dmz'd" as best as I could the router's firewall, and set up ZoneAlarm, since I don't believe Windows Firewall allows opening port ranges either. At least I didn't see such an option when I looked it over. I'd rather use Windows Firewall but I don't know if it can do what I need it to do. However, if I use the recommended setting for Internet, the High security setting, I can't even browse the Internet. Medium setting works, but I hate feeling like I am jeopardizing something security-wise. Furthermore, I am feeling uneasy as to what ZA is considering to be the Trusted Zone. When I installed it, it identified a "network" which I assumed was the LAN (consisting of this computer (XP) and the 2nd computer (2K). I assigned that as the Trusted Zone because these two computers share folders and printers... I hope I did right. I'm sorry if this isn't making much sense but I'm not really used to dealing with firewalls. In the years past I've pretty much gone with default settings with whatever I've been using, so long as it has worked. I think this time around a lot more tweaking is needed. This is the scenario: Two computers, one is a DELL running XP Pro, the other is a COMPAQ running Windows 2000 Advanced Server (My father-in-law's old copy, he didn't need it anymore and I don't have the workstation version so I'm running that as a desktop OS). Both are connected to a Zonet ZSR0104CP router, which is then connected to a cable modem, Arris TM402G/110. The Arris, as far as I know, doesn't have any firewall capabilities. The router DHCPs the two comps from a range of two possible IPs. The Zonet doesn't have firewall set up because its firewall cannot be configured correctly for an application on the DELL to be able to function. The DELL is running ZoneAlarm. The COMPAQ at the moment has no firewall configured. Then again it is a server OS so I'd assume it's relatively locked down by default. Some questions: 1. Does the COMPAQ need to be running its own firewall application? 2. The Trusted Zone in ZoneAlarm is specified as 192.168.1.0. 192.168.1.1 is the router...what does 192.168.1.0 refer to? Since installing ZoneAlarm, web browsing has gotten slow, and I am getting server response failures for no reason. I feel like this is unnecessarily complicated. If you have any suggestions as to how make this simpler, I welcome the input.
__________________
Hello, World! Last edited by Core; Aug 19th, 06 at 1:06 AM. |
| Advertisement |
|
#2
|
||||
|
||||
|
Honestly, unless you're running some kind of server, a simple router should be sufficient enough in conjunction with Windows Firewall.
I've found ZA to just be bloatware for most people.
__________________
Podcasts: http://www.hak5.org; http://securabit.com Xbox Live gamer tag: dualism Games: GTA 4, COD4 |
|
#3
|
||||
|
||||
|
Hmmm, yes... If Windows Firewall could be config'd to allow port ranges, I'd use it instead. I am not sure why you mentioned the router; as it is the router is not blocking anything; it is allowing incoming packets through ALL ports, which is the only way this will work. Hence the software-based, 3rd party firewall.
__________________
Hello, World! |
|
#4
|
||||
|
||||
|
To start off answering your specific questions
Quote:
Quote:
Quote:
I hope this helped.
__________________
A wise man can learn more from a foolish question than a fool can learn from a wise answer. ~Bruce Lee Last edited by Cryptoboats; Dec 21st, 06 at 8:58 AM. Reason: Spelling |
|
#5
|
||||
|
||||
|
Yeah, if you're looking for a more custom solution, then i'll give this a few mins of thought. It all depends on what you're protecting honestly.
If you really needed to have that range specifically open for something, there are ways to do it without using bloatware.
__________________
Podcasts: http://www.hak5.org; http://securabit.com Xbox Live gamer tag: dualism Games: GTA 4, COD4 |
|
#6
|
||||
|
||||
|
Thanks for the replies, fellas.
My 2nd computer died again, the hard drive won't run, so I guess that solved my networking problem. I can just forget about the router for now. I appreciate the replies, especially the bit about configuring Windows Firewall was interesting and educational.
__________________
Hello, World! |
![]() |
| Tags |
| config, confusion, firewall |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| NAV Auto-Protect-unable to find config files | bballman | Windows Legacy (95,98,ME,NT,2000) | 6 | May 4th, 05 5:10 AM |
| Do I need my Firewall still? | Tisatashar | System Security | 9 | Mar 3rd, 05 4:51 AM |
| Wireless Adapter Confusion.. | Oroc | Networking | 3 | Feb 22nd, 05 12:43 PM |
| New.net/Firewall/p2p, etc.... | a8000 | Internet | 6 | Feb 10th, 05 3:08 PM |
| Hardware trouble/confusion/advice | giff82 | General Hardware | 3 | Jan 26th, 05 3:11 AM |