hey guys need a quick favor does anyone know of a product that is a passive firewall
meaning it doesnt have to be the local gateway to do its job filtering
i have a company that wishes to continue using their software filter but they want firewall protection and i wanna do it right not have 2 nat servers working on 1 connect
anyone know of anything?
passive firewall?
- TheSovereign
- Posts: 2957
- Joined: Mon Apr 15, 2002 4:03 am
- Location: chicago
- Contact:
passive firewall?
<a href="http://www.youtube.com/watch?v=67rc96joOz8#t=0m58s">YodelRoll!</a>
<a href="http://www.halfinchbullet.com/">Goto HalfInchBullet.com!</a>

<a href="http://www.halfinchbullet.com/">Goto HalfInchBullet.com!</a>

- FlyingPenguin
- Flightless Bird
- Posts: 33161
- Joined: Wed Nov 22, 2000 11:13 am
- Location: Central Florida
- Contact:
There's nothing wrong with "stacking" NAT routers. I do it all the time. Nowadays most of your DSL ISPs give you a modem/router and not just a bridged modem. If you need to have a router after it then you have two choices: stack the routers (which does make port forwarding a little bit more complicated - you need to forward all ports fro mthe first to the 2nd router and then forward from the 2nd router to the specific PC) or ask the ISP how to reconfigure the modem as a "bridged" modem (disabling the modem's NAT router) so you're directly exposed on your public IP address.
While I have stacked routers, I do like to use a bridged DSL connection around here because Sprint's routers (the only DSL ISP in town) doesn't stealth all it's ports. Any decent off-the shelf $50 router nowadays stealths all it's ports so I'd rather have my router sitting on the public IP. Not so important maybe, but it might invite extra traffic from port scanners which could bog down the connection.
While I have stacked routers, I do like to use a bridged DSL connection around here because Sprint's routers (the only DSL ISP in town) doesn't stealth all it's ports. Any decent off-the shelf $50 router nowadays stealths all it's ports so I'd rather have my router sitting on the public IP. Not so important maybe, but it might invite extra traffic from port scanners which could bog down the connection.
---
“The Government of Spain will not applaud those who set the world on fire just because they show up with a bucket.” - Prime Minister of Spain, Pedro Sánchez

“The Government of Spain will not applaud those who set the world on fire just because they show up with a bucket.” - Prime Minister of Spain, Pedro Sánchez

- TheSovereign
- Posts: 2957
- Joined: Mon Apr 15, 2002 4:03 am
- Location: chicago
- Contact:
i guess its the purist in me, but stacking nat to me is very bad ive seen some issues with SSL over natx2
and these are corporate connections
professional all the way i dont care if the firewall costs 5k
and these are corporate connections
professional all the way i dont care if the firewall costs 5k
<a href="http://www.youtube.com/watch?v=67rc96joOz8#t=0m58s">YodelRoll!</a>
<a href="http://www.halfinchbullet.com/">Goto HalfInchBullet.com!</a>

<a href="http://www.halfinchbullet.com/">Goto HalfInchBullet.com!</a>

- FlyingPenguin
- Flightless Bird
- Posts: 33161
- Joined: Wed Nov 22, 2000 11:13 am
- Location: Central Florida
- Contact:
- TheSovereign
- Posts: 2957
- Joined: Mon Apr 15, 2002 4:03 am
- Location: chicago
- Contact:
- FlyingPenguin
- Flightless Bird
- Posts: 33161
- Joined: Wed Nov 22, 2000 11:13 am
- Location: Central Florida
- Contact:
So if I understand there's web filtering software on their existing router they want to keep?
You might look into the Astaro Security Appliance. They're all supposed to be gateways (NAT routers) though, but they're sophisticated enough that you might be able to use them as a firewall only.
http://www.astaro.com/products/security_appliances
You can also download a free linux distro of their gateway software an run it on on an old PC. I haven't tried it yet but it's supposed to be good.
I honestly don't think anyone makes a straight firewall without a NAT router anymore. Part of the function of modern firewalling is to reject unsolicted incoming traffic, and there is no better way to do that than with a NAT router.
You might look into the Astaro Security Appliance. They're all supposed to be gateways (NAT routers) though, but they're sophisticated enough that you might be able to use them as a firewall only.
http://www.astaro.com/products/security_appliances
You can also download a free linux distro of their gateway software an run it on on an old PC. I haven't tried it yet but it's supposed to be good.
I honestly don't think anyone makes a straight firewall without a NAT router anymore. Part of the function of modern firewalling is to reject unsolicted incoming traffic, and there is no better way to do that than with a NAT router.
---
“The Government of Spain will not applaud those who set the world on fire just because they show up with a bucket.” - Prime Minister of Spain, Pedro Sánchez

“The Government of Spain will not applaud those who set the world on fire just because they show up with a bucket.” - Prime Minister of Spain, Pedro Sánchez
