This is a read-only archive. No new posts or registrations. Privacy Page
Software

NAT Router - Hardware Firewall

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I tried to make this Topic on Discussion Forum: Security - Best Practices and Prevention, but not have permission.



Firewalls are generally used to prevent unauthorized access to computers or networks and it is a obligatory tool against malware infections.

If you are not happy with Windows firewall and want to spend some money for brand pro firewall please read first Gibson Research Corporation (GRC) thinking and recommendation.

Hardware Firewalls/NAT (Network Address Translation) Routers

“External firewall and NAT router appliances provide excellent "natural protection" from external intrusion hacking. For systems where a NAT router makes sense (i.e. multiple machines sharing a single Internet connection) we highly recommend the use of a good NAT router. There is no better and more secure solution than running a single, external, NAT router — providing redundant external intrusion protection — coupled with copies of the FREE ZoneAlarm firewall — providing the PC industry's most comprehensive internal extrusion management. The money you save by running the free ZoneAlarm firewall on multiple computers more than pays for a NAT”! – GRC
GRC goes further – “With a NAT router protecting your connection to the Internet — even if you only have one computer on the LAN behind the router — none of the Internet scanning and worms and hackers and other annoying and malicious Internet nonsense can get to your computer”.

More details about NAT:
1. NAT performed by the router allows multiple computers (machines) connected to the LAN behind the router to communicate with the external Internet.
2. One of the key benefits of NAT routers is that the router appears to the Internet as a single machine with a single IP address. This effectively masks the fact that many computers on the LAN side of the router may be simultaneously sharing that single IP.
3. All NAT routers inherently function as very effective hardware firewalls. As a hardware firewall they prevent "unsolicited", unexpected, unwanted, and potentially annoying or dangerous traffic from the public Internet from passing through the router and entering the user's private LAN network.
4. Since the NAT router links the internal private network to the Internet, it sees everything sent out to the Internet by the computers on the LAN. It memorizes each outgoing packet's destination IP and port number in an internal "connections" table and assigns the packet its own IP and one of its own ports for accepting the return traffic. Finally, it records this information, along with the IP address of the internal machine on the LAN that sent the outgoing packet, in a "current connections" table. When any incoming packets arrive at the router from the Internet, the router scans its "current connections" table to see whether this data is expected by looking for the remote IP and port number in the current connections table. If a match is found, the table entry also tells the router which computer in the private LAN is expecting to receive the incoming traffic from that remote address. So the router re-addresses (translates) the packet to that internal machine and sends it into the LAN. If the arriving packet does not exactly match traffic that is currently expected by the router, the router figures that it's just unwanted "Internet noise" and discards the unsolicited packet of data.

arTech
I always recommend the use of a router - and as noted above, that is even when it is a network of just one computer. It will not provide 100% assurance of security, but it sure provides a huge level not obtainable any other way. Also, I note that Steve Gibson wrote that a long time ago. Windows Firewall, which as always been a good firewall, BTW, has come a long ways since then, and in its latest version with Windows 7, has become an excellent firewall. While some would argue that ZoneAlarm has also gone a long way, but in the opposite direction!
Agree with your comments about ZoneAlarm which I used long time ago. I remember some conflicts with other software and strong restriction. Now my firewall is Outpost. It is very quiet firewall. Agree that Steve Gibson wrote that a long time ago, but my idea is to give attention on router usage and protection (ZA is only part of citation). I couldn't find newer respectable item about hardware firewall on Google and that is strange (to many items about commercial pro firewalls). However, with your and Gibson's comments, advice is very clear: router and Windows firewall coupled provide high level of protection even when it is a network of just one computer. arTech

Agree that Steve Gibson wrote that a long time ago, but my idea is to give attention on router usage and protection

Oh yeah. The advice is still very applicable today, perhaps timeless.
Don't forget Comodo Firewall. Perhaps a bit more technical then most, but it is the best free firewall out there (With ZoneAlarm 2nd because of an easier interface)

With ZoneAlarm 2nd because of an easier interface

If easier interface is your criteria, then I'd put Windows Firewall way ahead in first place. Not only is it an excellent, effective firewall, but the interface is very simple, and does not nag, nag, nag.

With ZoneAlarm 2nd because of an easier interface

If easier interface is your criteria, then I'd put Windows Firewall way ahead in first place. Not only is it an excellent, effective firewall, but the interface is very simple, and does not nag, nag, nag.

By that, I was saying that Zone Alarm is the best firewall with a user-friendly interface. But Comodo is the best firewall full stop (I am talking about free ones)
Hello -Redeye-,

By that, I was saying that Zone Alarm is the best firewall with a user-friendly interface.

FYI. :)
September 2010.
Seven page topic: http://forums.zonealarm.com/showthread.php?t=75332

http://it.slashdot.org/story/10/09/20/2037233/ZoneAlarm-Employs-Scare-Tactics-Against-Its-Users

Best regards.
Yeah, that behavior is just unacceptable. Security entities MUST adhere to, and be held to a "higher standard" so there is not even the appearance of improprieties.

Also disturbing is CP's reply indicating just about anyone in the company can speak for the company. It is really sad because for years, ZA was the indisputable king of firewalls. But, they got greedy.
This is exactly what I am talking about. To many forums, reviews, Top ten sites - which firewall is better! There are many commercial firewalls on the market. Marketing. Throw money away. Recently have found excellent almost forgotten information written long time ago: There is no better and more secure solution than running a single, external, NAT router coupled with firewall — providing high level of protection not obtainable any other way. Here Windows firewall is more than enough. arTech

Windows firewall is more than enough.

It actually always has been too. Even when first introduced way back with earlier versions of XP as ICS, Internet Connection Sharing. But it got slammed by MS bashers and the biased IT press (funded by ZA, no less) for (1) being disabled by default and (2) being only a 1-way firewall, blocking only unauthorized incoming access attempts. What these same bashers neglected to mention was that (1) MS was getting sued right and left for integrating a photo editor, calculator, browser, games and was already shot down for attempting to integrate an AV. And (2) the only reason you might need outgoing firewall support is if some malicious code made it past all your defenses on the way in! And about the only way that could, and still today can happen is if the user, always the weakest link, failed to keep their system updated, patched, scanned and blocked, or failed to avoid risky practices.
Hmmmmmm, I didn't know about ZoneAlarm's scaremongering tactic but they have gone down in my respect :angry: At least Comodo is run by a guy who also makes Youtube vids to help keep everyone up-to-date on sucurity matters

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI