Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Router Config: Just Use Defaults? Why/Why Not?
Search Topic:
Uniqs:
176
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Zone Alarm Pop-Ups Messages »
« Improve Wifi Security When Using Public Hotspot???  
AuthorAll Replies


BuckShot7
Am I Going Bald?

join:1999-12-10
Smyrna, GA

Router Config: Just Use Defaults? Why/Why Not?

Given the number of viruses that seem to be plaguing everyone, I thought I'd better tighten up my home system/network. I've never "configured" my Linksys BEFW11S4 V.2 router other than MAC address cloning and I don't even do that anymore. But I'm concerned I'm not getting the best protection (I do run Sygate's personal firewall on all connected PC's.) Are there settings or changes I shoudl make with regard to port blocking, filtering etc? Or is the default configuration ok to stick with? Thanks,

Carr

join:2003-06-20
Gardendale, AL

Interesting question-- I am running a LinkSys BEFSX41 router and Zone Alarm Pro here on an XP Pro system . Other than changing the default password on the LinkSys setup and MAC cloning, Im also running the Firewall portion of things pretty much default. My settings (and they are default on this router) are as follows:

Advanced firewall protection enabled
Web filtering section (and this is where Im uncertain)
Proxy: Allow
Java: Allow
ActiveX:Allow
Cookie:Allow

I also would appreciate hints and suggestions from the experts here about settings.

Thanks
Carr McCormack

adambpsu
Adam
Premium
join:2003-02-08
Harrisburg, PA
reply to BuckShot7
Well, I personally block WAN Requests on my LAN.
--
Adam... Also Known As Blue

Carr

join:2003-06-20
Gardendale, AL
reply to BuckShot7
Correct thats done by default here as well


z0ned

join:2002-07-27
Los Angeles, CA

reply to BuckShot7
The default configuration puts your LAN behind NAT, which in and of itself blocks un-initiated-from-your-side incoming TCP connections from the WAN, unless you have forwarded ports or created a DMZ. NAT routing is not a firewall, but it's better than being wide open.

People who will get infected by outbreaks like the recent ones are people whose machines have exposed (routable public) IP addresses and no software safeguards, and thus are wide open, largely dialup users, and users that plug a single client straight into their broadband modem, and are newbie enough to not have software firewalls and scanners. Which unfortunately, apparently, constitutes hundreds of thousands, if not millions, of U.S. users.

Or, another population of likely targets includes corporate machines which nobody has maintained for months because it was assumed they were safe on the private intranet, until the threat gets loose inside.

If you want to get proactive there are many tools to audit yourself. There are port scanners that will test the stealthiness of your network to the outside, and there are software "scoring" tools that check the configuration of individual client machines. The main thing that you cannot account for is humans. Your girlfriend. Your cousin's kid. They will come on when you're not looking and install some godforsaken evil program. So watch people closely around your expensive toys.
Forums » Up and Running » Security » SecurityZone Alarm Pop-Ups Messages »
« Improve Wifi Security When Using Public Hotspot???  


Tuesday, 24-Nov 08:12:42 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [90] New AT&T Ad Campaign Hits Back At Verizon
· [62] New Bill Takes Aim At Higher Verizon ETFs
· [30] AT&T Offers New Prepaid Wireless plans
· [29] Earthlink Suffers From Major E-mail Outage
· [27] Frontier Increases Modem Rental Fee
· [13] Vivendi In Way Of Comcast's NBC Desires
· [12] Charter Still Fighting With Creditors
· [7] Monday Morning Links
· [0] Time Warner Dallas Customers Get WiMax December 1
Most people now reading
· Windows 7 boot manager editing questions [Microsoft Help]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Big Bank Alternative to Bank of America? [General Questions]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· IE8 InPrivate filter from adblock plus list [Microsoft Help]
· Using DIR-615 C1/3.01 with Trendnet TEW-652BRP in N Mode [D-Link]
· linux box alternative to NetEqualizer ? ? Does it exist? [Wireless Service Providers]
· Security Software Updates - 24 Nov 2009 [Security]
· What to use while demonoid is down? [Filesharing Software]