How important is a firewall to you? Do you think a hardware based firewall for your box with intrution detection and stateful packet inspection would be a usefull/wanted feature?
Thanx For the input.
Jay Silver ICQ: 103463692 [email protected]
www.dedicatednow.com
Dedicated Hosting for the Masses.
It is very important couse last month some hackers ruined my comp and i didn't have any protection
I lost many content which i didn't have back up
So from now on i structly recomanded to anyone who have anything important on his computer
Originally posted by Lykos It is very important couse last month some hackers ruined my comp and i didn't have any protection
I lost many content which i didn't have back up
So from now on i structly recomanded to anyone who have anything important on his computer
Would be a more useful comment if you stated how exactly they ruined or gained access to your system. In most cases turning off retarded shit like Inetd for your daemons is a good start. After that allowing only ssh ftp is a good step. Of course no telnet, ssh2, although not necessary. If you have only a few locations that you can connect from you can use your OS's default firewall to secure port 22 to only specific locations which will save a shitload of trouble. After that close down all ports that arent in use, mostly just http,ssh,ftp,named should be open, smtp and pop or imap if you are running it. Sockstat -l in freebsd to see whats listening on what.
Just a few basic precautions and you have already made your system that much more difficult to break into. Nothing is 100% secure but the majority of breakins are because systems are left wide open, not because a lot of work was done breaking them. After all a random attacker usually wont spend a week breaking into your system unless he has something specific he wants to accomplish, but in that case he isnt exactly a random attacker anymore.
A good firewall can save your ass from lots
and lots of work rebuilding for sure.
But It's also handy to keep up to date with security
for the operating system used on your server
as a firewall may not beable to save you from
all attacks. Eg: If your webserver software has
a security bug in it a frewall may very well not
help you.
A healthy balance definitly includes firewall + up-to-date software.
As for Hardware Vs Software firewalls...
Depending on your operating system a hardware
firewall may not be as flexible as some of the software
equivelants getting around nowa days.
Comment