Favorite Software Firewall
#16
FlyerTalk Evangelist


Join Date: Aug 2001
Programs: DL GM, AA Gold, Hilton Diamond, Bonvoy Plat
Posts: 12,171
Pretty happy with Norton Internet Security.
I'd also second Scott's vote for a hardware firewall, but I like the software firewall's ability to specifically block outbound traffic, like the annoying efax.com popup program.
I'd also second Scott's vote for a hardware firewall, but I like the software firewall's ability to specifically block outbound traffic, like the annoying efax.com popup program.
#17
In Memoriam




Join Date: Jun 2000
Programs: Honors Diamond, Hertz Presidents Circle, National Exec Elite
Posts: 36,111
Anything new here? 
I too am behind a router at home (but like having both belt and suspenders
) and also want a firewall when at public wifi hotspots or glomming onto someone's network.
I've been playing with the Comodo Firewall
http://www.comodo.com/ It gets very good reviews.
I finally dumped Zone Alarm because it basically stopped working.
Or is Windows XP's built-in firewall enough when out in public?

I too am behind a router at home (but like having both belt and suspenders
) and also want a firewall when at public wifi hotspots or glomming onto someone's network.I've been playing with the Comodo Firewall
http://www.comodo.com/ It gets very good reviews.
I finally dumped Zone Alarm because it basically stopped working.
Or is Windows XP's built-in firewall enough when out in public?
#19
A FlyerTalk Posting Legend




Join Date: Sep 2002
Location: LAX/TPE
Programs: United 1K, JAL Sapphire, SPG Lifetime Platinum, National Executive Elite, Hertz PC, Avis PC
Posts: 47,175
Anything new here? 
I too am behind a router at home (but like having both belt and suspenders
) and also want a firewall when at public wifi hotspots or glomming onto someone's network.
I've been playing with the Comodo Firewall
http://www.comodo.com/ It gets very good reviews.
I finally dumped Zone Alarm because it basically stopped working.
Or is Windows XP's built-in firewall enough when out in public?

I too am behind a router at home (but like having both belt and suspenders
) and also want a firewall when at public wifi hotspots or glomming onto someone's network.I've been playing with the Comodo Firewall
http://www.comodo.com/ It gets very good reviews.
I finally dumped Zone Alarm because it basically stopped working.
Or is Windows XP's built-in firewall enough when out in public?
Comodo seems to be stable, nicely designed and works without chewing up my resources; I'm happy so far.
#20
Join Date: Aug 2007
Programs: AA EXP, HH Gold, SPG Gold, Marriott Gold
Posts: 3,017
As an IT guy, I think safe computing habits and the XP integrated firewall are sufficient for general public access points. BTW, the "computing habits" are a MAJOR factor.
There are too many idiot users out there who expect software/hardware to protect them from themselves. It's like a condom: sure, it'll protect you, but don't go putting it in high-risk places.
Browse safely this holiday season, folks. Oh, and flies spread disease...so keep yours closed.
There are too many idiot users out there who expect software/hardware to protect them from themselves. It's like a condom: sure, it'll protect you, but don't go putting it in high-risk places.
Browse safely this holiday season, folks. Oh, and flies spread disease...so keep yours closed.
#21




Join Date: Jul 2005
Location: Atlntida, Canelones, Uruguay (MVD) and rarely GNV
Programs: AV LifeMiles, CM ConnectMiles, BA Exec Club. Former:ex-ASGold, ex-UA1K, ex-COPlat, ex-NWGold.
Posts: 2,672
Disagree with some of the upthread comments about not needing a firewall while doing WiFi, since WiFi is easily hacked.
The primary purpose of having a firewall on your Windows laptop (or home PC, but for now let's talk laptop on a public access point) is not to prevent WiFi hacking. It's to lessen the chance your PC from being exposed to exploits on the public internet. Stealthing ports, preventing unusual inbound and outbound access, etc. Making it less likely that the latest zero-day exploit or patch-available but not-yet-patched will own your machine, make it part of a botnet, install a rootkit, etc.
The general consensus is that an unpatched Windows machine, unfirewalled, connected to the public internet (whether via Wi-Fi or ethernet cable, if connected to a well-known IP provider like Comcast, Verizon, Qwest, Sprint, T-Mobile, whatever) will be infected within 10-30 minutes.
That's what the firewall is for. Not for protecting you from the guy on the other side of the RCC sniffing your packets.
Also - big reason for using a 3rd party software firewall, whether it's Norton, McAfee, Comodo, ZoneAlarm or whatever: They all provide firewall protection for outbound connections. The built-in Windows firewall, at least in XP, only protects against inbound. If some malware is on your machine already, unknown to you, trying to contact the mothership, the Windows firewall does nothing to stop its outbound connection attempt. The third-party firewalls add this protection.
The primary purpose of having a firewall on your Windows laptop (or home PC, but for now let's talk laptop on a public access point) is not to prevent WiFi hacking. It's to lessen the chance your PC from being exposed to exploits on the public internet. Stealthing ports, preventing unusual inbound and outbound access, etc. Making it less likely that the latest zero-day exploit or patch-available but not-yet-patched will own your machine, make it part of a botnet, install a rootkit, etc.
The general consensus is that an unpatched Windows machine, unfirewalled, connected to the public internet (whether via Wi-Fi or ethernet cable, if connected to a well-known IP provider like Comcast, Verizon, Qwest, Sprint, T-Mobile, whatever) will be infected within 10-30 minutes.
That's what the firewall is for. Not for protecting you from the guy on the other side of the RCC sniffing your packets.
Also - big reason for using a 3rd party software firewall, whether it's Norton, McAfee, Comodo, ZoneAlarm or whatever: They all provide firewall protection for outbound connections. The built-in Windows firewall, at least in XP, only protects against inbound. If some malware is on your machine already, unknown to you, trying to contact the mothership, the Windows firewall does nothing to stop its outbound connection attempt. The third-party firewalls add this protection.
#22
Suspended
Join Date: Jul 2007
Programs: AAdvantage, SkyMiles, USAir, Singapore, BA
Posts: 602
Actually, there's no such thing as a "hardware" firewall. There are firmware firewalls that come loaded in a box with connectors on it, but it's still good old code that's inspecting packets and deciding what to do. There are no gears and levers in there that hackers can't penetrate.
Firmware firewalls might offer marginally better protection (because an intruder has to figure out how to re-flash the program memory), but good software implementations have ways of preventing their own code from being corrupted, so the margin of superiority is extremely slim.
Firmware firewalls might offer marginally better protection (because an intruder has to figure out how to re-flash the program memory), but good software implementations have ways of preventing their own code from being corrupted, so the margin of superiority is extremely slim.
Last edited by CessnaJock; Jan 1, 2008 at 8:41 pm
#23
 



Join Date: Nov 2000
Location: Upcountry Maui, HI
Posts: 13,708
The term is generally used to describe an appliance that has a built-in firewall, as opposed to loading a software program on your computer that does the firewall function.
It doesn't really matter how the firewall is implemented in the appliance (eg, router) as long as the function is built-in to the appliance. It's all software at the end of the day, but that doesn't really matter. (Does it matter if your washer/dryer has a computer program driving the display, controls and operation of the appliance?)
-David
It doesn't really matter how the firewall is implemented in the appliance (eg, router) as long as the function is built-in to the appliance. It's all software at the end of the day, but that doesn't really matter. (Does it matter if your washer/dryer has a computer program driving the display, controls and operation of the appliance?)
-David
#24
Suspended
Join Date: Jul 2007
Programs: AAdvantage, SkyMiles, USAir, Singapore, BA
Posts: 602
If that's true, why do I get popups from Windows Firewall saying "Program such-and-such wants access to the internet. What do you want to do?"
#25
Original Member

Join Date: May 1998
Location: Portland OR Double Emerald (QF and AA), DL PM/MM, Starwood Plat
Posts: 19,593
But outbound filtering is turned off by default, and turning it on is much more difficult than controlling inbound filtering. Probably beyond the interest and abilities of most Vista users (have to use MMC and Advanced Security Group policy -- big pain in the neck, and a really flawed implementation).
I use SystemSuite (by Avanquest) which includes an effective firewall (NetDefense) which is not resource hungry and works well on Vista. For XP there are lots of other firewalls that work well and are cheap (often free). Sticking with the Windows firewall is probably a poor choice for most people, unless you are willing to spend a lot of time administering it. If you don't know what administration it requires, then it is a really poor choice (it will leave your system vulnerable).
#26
 



Join Date: Nov 2000
Location: Upcountry Maui, HI
Posts: 13,708
Keep in mind that the OP was from 4 years ago. When the XP firewall first came out, I believe it was uni-directional only. I think it's changed since then, but I've never used it.
FWIW, I put the free version of zone alarm on a new laptop I setup with XP Pro. It seems to work ok for me. Lot's of pop-ups, but that's to be expected when it's new and you haven't trained it yet. My older laptop had a Symantec Corporate firewall. I didn't particularly like that one, but I lived with it for a long time. It did work, but it was annoying in some ways.
-David
FWIW, I put the free version of zone alarm on a new laptop I setup with XP Pro. It seems to work ok for me. Lot's of pop-ups, but that's to be expected when it's new and you haven't trained it yet. My older laptop had a Symantec Corporate firewall. I didn't particularly like that one, but I lived with it for a long time. It did work, but it was annoying in some ways.
-David
#27
Join Date: Nov 2002
Location: San Francisco, CA
Programs: US CP, *wood Gold, Marriott gold, Hilton something
Posts: 1,458
So, focus more in the central side (your email etc...) and consider either setting up a simple VPN at home or asking if your ISP supports secure pop connections. A firewall looks nice and reports a load of attempts, but unless you have something open on your machine then the WinXP firewall will be more than sufficient.
For software firewalls I am smitten with Blink
http://www.eeye.com/html/consumer/pr...ink/index.html
Blink, from Eeye, is free for personal use. I am convinced its the most effective firewall/malware/spyware/adware toolkit available and its very lightweight. It takes up a fraction of the memory/cpu footprint that just one of those applications alone normally takes... in short, I'm zealous about it to the point of not building an XP box without it.
#29
 



Join Date: Nov 2000
Location: Upcountry Maui, HI
Posts: 13,708
#30
In Memoriam




Join Date: Jun 2000
Programs: Honors Diamond, Hertz Presidents Circle, National Exec Elite
Posts: 36,111
Thanks, LIH Prem. I was very confused by his statement.
While I really liked Comodo, I ended up removing it because I never could get it to play nice with my two print servers. That was probably my fault/impatience, though.
While I really liked Comodo, I ended up removing it because I never could get it to play nice with my two print servers. That was probably my fault/impatience, though.
The term is generally used to describe an appliance that has a built-in firewall, as opposed to loading a software program on your computer that does the firewall function.
It doesn't really matter how the firewall is implemented in the appliance (eg, router) as long as the function is built-in to the appliance. It's all software at the end of the day, but that doesn't really matter. (Does it matter if your washer/dryer has a computer program driving the display, controls and operation of the appliance?)
-David
It doesn't really matter how the firewall is implemented in the appliance (eg, router) as long as the function is built-in to the appliance. It's all software at the end of the day, but that doesn't really matter. (Does it matter if your washer/dryer has a computer program driving the display, controls and operation of the appliance?)
-David

