PPRuNe Forums - View Single Post - Which wireless manufacturer?
View Single Post
Old 5th Dec 2008, 15:33
  #4 (permalink)  
Saab Dastard
Spoon PPRuNerist & Mad Inistrator
 
Join Date: Sep 2003
Location: Twickenham, home of rugby
Posts: 7,414
Received 280 Likes on 179 Posts
If your current firewall provides what I listed then I would say that is adequate for a hobby website.

If you are running a business or hosting confidential data then you might want to increase the security with a device such as you suggest.

It brings IDS to alert you to suspicious / malicious behaviour as well as higher layer packet inspection. The DoS protection could be useful if anyone feels strongly enough to launch such an attack - but why should they unless it's a commercial site?

It is unlikely that the VPN support is of much interest to you, unless you or others need to access your network from outside - other than the web services you are making available.

Still, for £20 it's maybe worth your peace of mind.

How you decide to implement it depends very much on your current equipment and security requirements / policy.

If you currently have a combined adsl modem / router / firewall / Wifi access point (WAP), that is probably the least preferable, in the sense that your current network will be "beside" the firewall-protected network rather than behind it.

Ideally it should be located between the modem and the existing WAP / router / Firewall, as it would then protect the entire internal network. You would use an existing WAP / router / firewall primarily as just a WAP, connecting its internet uplink port to one of the downlink ports on the new firewall. You might well have to experiment with the configurations to get everything working correctly.

Also bear in mind that only one of these devices should be a DHCP server, not both!

Depending on how the devices are configured, you may be able to put any servers in a DMZ separate from the rest of the home network, which could have advantages.

A thorough and careful review of the manual to understand the capabilities and options of the device is recommended!

SD
Saab Dastard is offline