Forum     

Go Back   Digit Technology Discussion Forum > Portables, Peripherals and Electronics > QnA (read only)
Register FAQ Calendar Mark Forums Read

QnA (read only) Mods please help transfer the contents of this forum to proper sections. :)


 
 
LinkBack Thread Tools Search this Thread Display Modes
Old 17-01-2005, 03:29 PM   #1 (permalink)
In The Zone
 
Join Date: May 2004
Location: Mumbai
Posts: 463
Default What are the Advantages of a Hardware Firewall


Hi All

Can any one tell me exactly what are the real advantages of a
hardware based firewall over a software one.

Except its a seperate box and doesn't interfere or load the CPU.

Waiting for your replies
quad master is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 17-01-2005, 04:11 PM   #2 (permalink)
Alpha Geek
 
Join Date: Feb 2004
Location: Belgaum
Posts: 745
Default

Well I will sum up with
Pros
1.Resources-All the resources are handled by the hardware firewall.Inbound attacks are all carried out at its expense.

2.Extra features & functions-SPI(Stateful Packet Inspection),Packet Filtering,Port Forwarding...These give a tad bit more security as against software firewalls.

3.Customisation-Placing a service for the public[internet] in the DMZ(Demilitarised Zone) becomes much more easier with added security.
Rules can be setup for blocking/allowing a range of ports.

4.They will protect the entire network which is not the case in software firewalls.You will have to install & configure a software firewall on each machine on the network + the rules.

Cons
1.But one thing that doesnt quite work well with hardware firewalls is outbound traffic.It considers everything leaving you internal network as legit.

Software firewalls work well in this regard of inspecting inbound services that are trying to access the internet.

This is what I could think of right now,anyways all in all a hardware firewall works good for a large network.For a home based network you are better off with a software firewall plus a NAT router with maybe SPI if you can afford.
__________________
The protection of a machine is a process & not a given -Duane Arnold.
www.Oobertech.net
Look ma my blog http://techhub.blogspot.com/
digen is offline  
Old 17-01-2005, 05:44 PM   #3 (permalink)
In The Zone
 
Join Date: May 2004
Location: Mumbai
Posts: 463
Default

Hey Thanks m8
quad master is offline  
Old 17-01-2005, 06:29 PM   #4 (permalink)
Alpha Geek
 
Join Date: Feb 2004
Location: Belgaum
Posts: 745
Default

Hope it helped.
__________________
The protection of a machine is a process & not a given -Duane Arnold.
www.Oobertech.net
Look ma my blog http://techhub.blogspot.com/
digen is offline  
Old 18-01-2005, 05:43 AM   #5 (permalink)
In The Zone
 
Join Date: Mar 2004
Location: kolkata
Posts: 255
Default

Hi Digent Verma , what if i use a computer with 2-3 Lan cards , install Win2k3 Server , install Routing and Remote Access and use it as a Router ?
__________________
AMD64 2800+ 1GB ECC DDR 400 ,MSI K8T800 Asus Geforce FX 5200 128 MB, 120 GB Barracuda,16X DVD RW,Samsung 16x DVD,Samsung Wireless ,Creative AUDIGY2 ZS 7.1 with Creative Inspire 7.1/1800+AXP 512MB ECC DDR400 .40GB BLACK
indro is offline  
Old 18-01-2005, 06:16 AM   #6 (permalink)
In The Zone
 
Join Date: Sep 2004
Posts: 433
Default

It would be much more complex to set up your own. Not only do you have to figure out how to get windows server to work, fix all the crash bugs, you also need a much faster system. A router is designed to check the packets going by in real time and hence designed that way. Using windows, it has to move the data to memory, check it, run its rules and then move it back to the LAN card and send it. PCI is fast but when you have multiple nics and a lot of rules it will slow down quite a bit.

Also prices are much cheaper than equivalent PC hardware.. At least in the US. You can get fairly good routers for a few hundred bucks. The cost of just the windows software. Also the new routers also have options to scan for virus a and email stuff. Which makes it basically a pc anyway. But reliability wise a stand alone router is the way to go. None of that boot up or crash problems.
AlienTech is offline  
Old 18-01-2005, 03:28 PM   #7 (permalink)
Alpha Geek
 
Join Date: Feb 2004
Location: Belgaum
Posts: 745
Default

Quote:
Hi Digent Verma , what if i use a computer with 2-3 Lan cards , install Win2k3 Server , install Routing and Remote Access and use it as a Router ?
Sorry but I seem to have lost you there.And oh you cant install "routing".Basically a router is a hardware device which acts as a gateway also may have features such as Packet filtering,SPI...
Do you want to use a single machine as entirely for routing purposes?
Then why install win2k server dude.If you have a old machine lying around ,even a 486 will do then may I suggest you freeware solutions based on linux.These distros are built-in with features such as firewall,port blocking....Exactly what you need if you dont want to invest in a hardware router.

1.Clarkconnect-This one is very good considering the features it offers.Highly recommended by MVP's.

2.IPcop-Another good distro which is feature rich.

3.Smoothwall-Cool with lotsa options.

Configuring them is not hard if you go through the forums & documents posted at their respective sites.Get a few lan cards & a hub/switch whichever suits your pocket & you are on your way.

Quote:
Also the new routers also have options to scan for virus a and email stuff. Which makes it basically a pc anyway.
Are you kidding me?Can you atleast give me the company url which sells routers which scan for virus to backup whatever you posted?
__________________
The protection of a machine is a process & not a given -Duane Arnold.
www.Oobertech.net
Look ma my blog http://techhub.blogspot.com/
digen is offline  
 

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


 
Latest Threads
- by gforz
- by clmlbx
- by Sujeet

Advertisement




All times are GMT +5.5. The time now is 03:53 PM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2