Over the last couple of weeks I've been gathering opinions and experiences about hardware firewalls, but have still yet to reach a final conclusion. The question.. Is it actually worthwhile running a hardware firewall?
Some history; I run a small network at home, with five CLI Gentoo boxes and ADSL. One box runs limited services (apache, ssh) and the rest are clients/workhorses that require no incoming requests from the outside world (and to my knowledge do a rather fine job of ignoring such things).
From feedback I've received so far, there are some good opinions for running a hardware firewall...
And also some bad opinions...
I've searched the DefCon forums and found some vaguely relevant discussions (namely here and here), Skroo's recommendation of the Cisco Pix 501 is burnt into my retinas, and I now have a whole list of topics that need further research before choosing a firewall. Assuming I make the right one, the question still remains. Is it worth running one?
Opinions/experiences appreciated.
Some history; I run a small network at home, with five CLI Gentoo boxes and ADSL. One box runs limited services (apache, ssh) and the rest are clients/workhorses that require no incoming requests from the outside world (and to my knowledge do a rather fine job of ignoring such things).
From feedback I've received so far, there are some good opinions for running a hardware firewall...
- Makes up for having a shite ADSL router i.e. logs, activity/bandwidth reporting, and so on
- Probably provides some form of security against the most common attacks
- Provides said form of security between networks (e.g. wired, wireless)
And also some bad opinions...
- It complicates the network, opening more security holes than it prevents
- On a badly configured network, it's the equivelant of taking a rust-ridden car into the paint shop and asking for a "quick touch-up"
- And the funniest one I've heard yet, "Are you kidding me?". He WAS wearing a trenchcoat though.
I've searched the DefCon forums and found some vaguely relevant discussions (namely here and here), Skroo's recommendation of the Cisco Pix 501 is burnt into my retinas, and I now have a whole list of topics that need further research before choosing a firewall. Assuming I make the right one, the question still remains. Is it worth running one?
Opinions/experiences appreciated.
Comment