Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.
|
|||||||
Guide: Laptop Firewall security
![]() |
| Thread Tools |
|
#1
|
||||
|
||||
|
Guide: Laptop Firewall security
If like me, your laptop is your major system, then you might have concerns when
moving from your home LAN to a public hotspot -- at least I sure do! At home, I have a router as a perimeter defense. By avoiding all port forwarding, adding MAC filtering for DHCP address assignments, I have a tight environment and can allow a visiting friend to hook-up without concern. However, at a public hotspot, I do not have control of the router, loose my MAC filtering, and get exposed for file/print sharing issues as well as a host of known Trojans that visit various specific ports. My sole proactive defense becomes the firewall rules. My router is on 192.168.0.1 so the whole LAN subnet would normally be 192.168.0.1 -- thru 192.168.0.255. I've defined {home-lan} as 192.168.0.1-192.168.0.10 and where MAC filtering ensures only known devices and systems can reside in this range. Any visitors will be at 192.168.0.11 and above. {home-brdcst} is 192.168.0.255 The attachment is a screenshot of my firewall rules and the following text explains the usage of each. Firewall Rules: Known Issues: Rules 4-5 expose file sharing and everything else on this LAN. At a hotspot, this rule would be change to BLOCK or deny access Rules 21-22 explicitly block private networks 10.*.*.* and 172.16.*.*, one of which would be required to have any access at all. Both of these problems could be resolved by a firewall which implements the concept of a network profile: rules applied depending upon the specific adaptor and/or IP address configured. Norton IS has that feature, but like many others, I've elected to dump that product. Rules 13-16 are really redundant as rule 23 covers these cases. These are known trojan attack ports that would be defacto defeated just by the presence of my router. At a hotspot, there are known systems attached and I can't assume everyone is well intended. Details on Trojan Ports may be found here. Personally, I like documentation and this is where I elected to place it. Last edited by jobeard; 03-22-2007 at 04:57 PM. Reason: edit for bootp and dhcp in a hotspot |
|
#2
|
|||
|
|||
|
It helps me a lot, thanks.
|
|
|
![]() |
| Thread Tools | |
|
| Similar Topics | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| CA Internet Security 2007 (Firewall Issues) | RyuuKa | Misc. Software & Utilities | 3 | 01-19-2007 10:30 PM |
| Security Center Firewall is not working. | tech_Harry | Security and the Web | 3 | 01-17-2007 02:02 PM |
| Guide to Windows Online Security & Privacy thingy.. | Dayus | Windows OS | 4 | 07-30-2004 08:08 AM |
| Guide to Windows Online Security & Privacy @ TechSpot | Julio | Old Frontpage News & Comments | 1 | 07-26-2004 02:02 PM |
| Guide to Windows Online Security @ TechSpot | Julio | Old Frontpage News & Comments | 2 | 05-30-2003 01:02 PM |
All times are GMT -4. The time now is 12:47 PM.



