ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security management Toolkit

Firewalls - back to basics

Rupert Goodwins ZDNet.co.uk

Published: 09 Oct 2002 08:54 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

What is a firewall?
A firewall is software or hardware that sits between two networks -- typically, between your LAN and the Internet -- and allows some sorts of network traffic through while preventing others. It works by rules that you set, which define the sort of security you want. Unless you know what sort of security you want and can cast it in rules that your firewall understands, your firewall will be useless or worse.

A firewall can be a stand-alone network appliance, part of another network device such as a router or bridge, or specialist software running on a dedicated PC. The latter route is popular among Linux fans and is worth investigating if you have those skills and can cost your time to make it worthwhile. If you're reading this, the chances are you don't want to take this approach.

What's a 'personal' firewall?
Personal firewalls, like ZoneAlarm or BlackICE Defender, are software-only firewalls that run on the computer they protect. Designed for individual users or small networks, their primary function in the business environment is to protect remote users who access the network through a VPN or dial-up. Windows XP comes with a personal firewall.

If set up in conjunction with other security measures such as anti-virus software and maintained properly, they can be very effective. They are however prone to user tampering, can interact with other software on the computer and are vulnerable to attack by viruses or trojans running locally. Look for remote manageability and good usability, and train users on the proper action if the personal firewall reports an attack or a problem.

Do all firewalls work in the same way?
Inasmuch as they monitor traffic and block inappropriate activity yes. However, there are two major ways to do this -- at the network layer or at the application layer. The network layer style of firewall looks at packets and checks their source and destination addresses and port number, allowing them through or not on that basis. Application layer firewalls acts as proxies -- they don't allow traffic to pass between the two networks, but pretend to be applications when accessed from outside the protected network. The firewall then analyses the traffic to make sure its appropriate, and conducts its own conversation with the real application. This has the advantages over the network layer system of hiding all the details of the protected network from the outside world, and also allowing in-depth logging and control of packet movements. It is more complex to administer, more resource hungry and less flexible than the network layer system.

It is possible and increasingly common, for firewalls to mix and match aspects of both approaches.

What's a DMZ?
A rather unfortunate acronym which stands for demilitarised zone. It's an area with some firewall protection, but which is visible to the outside world -- and thus where public servers for web, file transfer, email and so on can live. More sensitive, private services such as internal company databases, intranets and so on live behind a further firewall and have all incoming access from the Internet blocked. You can also create an effective DMZ using just one firewall, by setting up access control lists that let a subset of services to be visible from the Internet.

How do I make FTP/Web/video conferencing, etc, work through my firewall?
With simple protocols, such as the Web's HTTP, this can be as simple as allowing access through one port. With complex protocols such as H.323 for videoconferencing, the security issues are non-trivial and, although you can make them work quite simply this may involve disabling dangerously large areas of your firewall's protection. For a specific question, you can check the Internet Firewalls FAQ but remember that many security problems are caused by half-understood or undocumented changes to a firewall's rule set.

How can I tell how good a firewall is before I buy it?
Concentrate on usability, support and reputation over feature sets, performance or price. Find existing users of the products you're interested in -- and who have similar skills and work in a similar environment, if possible -- and find out what their experience has been. Firewall users invariably congregate in online discussion groups, some of which are also frequented by the manufacturers, and are among the most voluble and opinionated of life forms.


Have your say instantly in the Tech Update forum.

Find out what's where in the new Tech Update with our Guided Tour.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
50 out of 83 people found this useful


Full Talkback thread

1 comment

  1. I have xp home p.c with the built in firewall. Ca... Anonymous

Company/Topic Alerts

Create a new alert from the list below:














Related Jobs

Network Engineer - Aberdeen - Up to 50,000

CCIE certification preferred but may be substituted with equivalent knowledge of routing, switching, and VoIP Expert level experience and hands on ...

Network Security Lead

Key Deliverables/Responsibilities: - Provide Technical expertise and overal guidance for all network and firewall matters to the local technical team ...

Linux / Cisco Systems Engineers - Oxfordshire

Key responsibilities: - Provide proactive day to day management and support for Internet related telecoms, server, router, firewall and back up ...

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment

Featured Talkback

It seems to me this is a burden being placed on the wrong shoulders. There is not an It system in the world that can stop an individual taking information in their heads and spewing out at the nearest undesirable third party.

By: RonaldWilkins

Read full story:
Deloitte: People are still weakest security link

DOWNLOAD

Security Essentials

Security Downloads

There are masses of security suites out there for small businesses. Here's a selection to get you started

Editor’s Rating
1 Norton 360™
2 AVG Anti-Virus Free Edition Rating: 10
3 PC Tools AntiVirus Free Edition
4 Kaspersky Internet Security

See All Software

In association with Symantec