 JTRockvilleData HoPremium,MVM join:2002-01-28 Rockville, MD Reviews:
·Verizon FiOS
| What's the WORST firewall? Just last week, I posted this question: Do I still need a firewall? »Do I still need a firewall?
Against the warnings of just about everyone who replied, I decided against installing a firewall. I lurk around here a bit, browsing the firewall related threads, and it seems like a big hassle. Anyway who would be out to get me?
Well, unfortunately, the events of this week have made me reconsider. I can answer the question of "Who is out to get me?" with the reply: Comcast!!!
I now have a renewed interest in firewalls, but I'm still a little hesitant. I don't want to become a slave to my firewall. My biggest concern is, although I can probably set up my primary email account using Outlook (Microsoft vs Comcast, kinda like rock vs hard place), EVENTUALLY I'm going to have to point my browser to Comcast.net to set up the additional email accounts. Before I do this, I definitely want some kind of shield.
That's why I've rephrased my question: What's the WORST firewall? I'm not ready for anything really complicated. In violation of my TOS, I use VPN, and apparently some firewalls are not VPN friendly. Other than that, I just want something *simple*, at least to begin with. My OS is W2k, and I have a router (US Robotics 8000).
Also, is there anything special I need to do with the router to make it more secure? --- Oops, my paranoia is showing! |
|
 Zhen-XjellProlific BunnyPremium,VIP,ExMod 2001-04 join:2000-10-08 Bordentown, NJ | said by JTRockville: What's the WORST firewall? I'm not ready for anything really complicated.
The kind you don't setup correctly or keep patched. -- Join a Distributed Computing Team at DSLR Today! Cure AIDS, Cancer, Diabetes, Alzheimer's and more! |
|
 JTRockvilleData HoPremium,MVM join:2002-01-28 Rockville, MD | reply to JTRockville Okay, okay, let me add this as a courtesy, to save all of you the trouble:
YOU TOLD ME SO --- I'm grasping at straws now... |
|
 Zhen-XjellProlific BunnyPremium,VIP,ExMod 2001-04 join:2000-10-08 Bordentown, NJ | I wasn't involved in that thread, I don't know what happened, so please don't read into my post as anything negative. It wasn't. |
|
 redxiiPremium,Mod join:2001-02-26 Sherwood, MI | reply to JTRockville Chill .
Z-X is right on that one. |
|
 proxy0Premium join:2001-08-03 Chicago, IL | reply to JTRockville The one you use and don't understand  |
|
 jabbawestOrbis HirsutisPremium join:2001-11-06 Lavon, TX Reviews:
·Cool Access
·TierOneNetworks
| reply to JTRockville Now that you have figured out you need a firewall. This little guy is easy to use and configure. Sygate Personal Firewall Try it for a week or two. Its free. If you don't like it. It's very easy to un-install. -- "America loves a winner, and will not tolerate a loser"Patton |
|
|
|
 No Name5You Only Regret What You Have Not Done. join:2000-01-26 Glendale, AZ | reply to JTRockville Yes firewalls are good. Do not think it would help with what Comcast was doing. You send data they intercept. Do not think I heard of them going into anyones computer that I know of. Just storing everything you sent. That said a firewall is good. Will stop lots of other bad stuff. Used Zone Alarm still have on wife's computer, no complaints. Heard some of the new ones are better. Use free version. Started using Tiny I guess now Kerio on mine. Some learning curve but seems to work ok while I am still learning tweaking. Supposed to be very good. Also the rules allow for more adjustment. Might help with VPN. Also they are free for home use. |
|
 jazzman916Life on the UpbeatPremium,MVM,ExMod 2004-10 join:2001-09-01 Birdland | Many prefer the "set it and forget" quality of Zone Alarm from »www.zonelabs.com.
After downloading and installing it will ask you the first time an application tries to access the net. You can decide if you want it to and have zone alarm remember your answer so it doesn't bother you anymore.
Most people then move to a rules based firewall. Tiny/Kerio and Sygate seem to be among the most popular. Give them all a try. If you don't like one then ditch it and try another! If you decide to take the rules based route there are many people here to help. Most importantly: use a firewall.
Happy, Safe surfing...  -- "Help save lives, join Team Discovery TODAY! |
|
 JTRockvilleData HoPremium,MVM join:2002-01-28 Rockville, MD Reviews:
·Verizon FiOS
| reply to Zhen-Xjell said by Zhen-Xjell: don't read into my post as anything negative
ditto I'm trying to be as light-hearted as I can. I was actually smiling when I wrote that This forum has been a godsend, as it's be a tremendously tough transition for me. I'll be forever grateful. said by nicki: Do not think I heard of them going into anyones computer that I know of.
I read that they do "port scans", at an alarming rate (from another user's post - the IP is Comcast's DNS server). At least it looks alarming to my non-firewall-familiar eyes: ---------------------------------------------------------- ISA Server name: PROXYC
ISA Server detected an all port scan attack from Internet Protocol (IP) address 68.48.0.5 ---------------------------------------------------------- said by jazzman916: "set it and forget" quality of Zone Alarm
Does the plain-n-simple ZA have VPN support? or do I need ZA Pro?
--- Please take me with a grain of salt. |
|
 JTRockvilleData HoPremium,MVM join:2002-01-28 Rockville, MD Reviews:
·Verizon FiOS
| reply to jabbawest said by jabbawest: This little guy is easy to use and configure. Sygate Personal Firewall
The information I found at the link you provided says they're "rules" based. This leads me to think that it'll take forever to set it up, in spite of your recommendation that it's easy to use and configure. Are "rules" something I should overcome my fear of? What is a "rule" anyway? |
|
 BlitzenZeusBurnt Out CynicPremium join:2000-01-13 kudos:2 Reviews:
·Frontier FiOS
| Rules are a list of instructions of what to allow, and block. There is no need to be afraid of them, and they allow for more complex/secure configurations.
They do require some knowledge, and a little bit of time to configure correctly.
The fact is the 'set and forget' people don't like these firewalls, but they are the ones that usually support VPN. -- ATTBI - AT&T Broadband Internet: Claims they are 'Lightning fast', but if they are lightning fast is OOL the speed of light?!? --Lightning does not move at the speed of light!-- |
|
 JTRockvilleData HoPremium,MVM join:2002-01-28 Rockville, MD | said by BlitzenZeus: Rules are a list of instructions of what to allow, and block.
I'm still confused. Are the rules a list of programs that I grant "internet" privileges to? |
|
 BlitzenZeusBurnt Out CynicPremium join:2000-01-13 kudos:2 Reviews:
·Frontier FiOS
| The rules can control applications also, but you don't have to control applications with them.
The simple firewalls only control allowing applications access to the net. The more secure firewalls let you control with protocols, and ports they use. -- ATTBI - AT&T Broadband Internet: Claims they are 'Lightning fast', but if they are lightning fast is OOL the speed of light?!? --Lightning does not move at the speed of light!-- |
|
 bbierRetired G.I., Member T.V.R.W.C.Premium join:2000-11-25 Centralia, WA | reply to JTRockville I have no problems getting VPN to work thru Zone Alarm (the free one). Should work just fine for you |
|
 jabbawestOrbis HirsutisPremium join:2001-11-06 Lavon, TX Reviews:
·Cool Access
·TierOneNetworks
| reply to JTRockville Download this PDF file for the third firewall on the list. This will help you understand what we are trying to tell you. »www.sygate.com/support/documentation.htm There is some good general info about certain terminology that has been discussed here and previously. Don't be so intimidated. You are making this harder than it really is. You need to read and read some more. Get something and try it. Then we can really help you more specifically. IMHO -- "America loves a winner, and will not tolerate a loser"Patton |
|
 JTRockvilleData HoPremium,MVM join:2002-01-28 Rockville, MD | reply to JTRockville THANK YOU --- Here I go! Read, read, read. |
|
 jabbawestOrbis HirsutisPremium join:2001-11-06 Lavon, TX Reviews:
·Cool Access
·TierOneNetworks
| said by JTRockville: THANK YOU Here I go! Read, read, read
Wasn't trying to run you off. Just trying to get you DIVE into the pool and try something, Our answers will be SO general until you have a specific firewall application we can target on and respond to appropriately. -- "America loves a winner, and will not tolerate a loser"Patton |
|
 cookeysPremium,MVM join:2001-06-10 Orland Park, IL | reply to JTRockville Hmmm. I have read 5000 threads entitled "What's the BEST firewall". Never seen one discussing the worst firewall. Of course the topic does now seem to be what is the BEST firewall. 
I like ZAP. It is easy to configure and forget about, and I have never had a problem with it. |
|
 MarkPremium join:2001-11-15 Phoenix, AZ kudos:1 | reply to JTRockville use ipchains |
|