|
Posted by john toynbee on September 6, 2007, 6:21 am
If you were Registered and logged in, you could reply and use other advanced thread options On Thu, 06 Sep 2007 08:19:51 +0000, Juergen Nieveler wrote:
>
>> Double firewalling is standard industry practice. Do you disagree? If
>> so I hope you are not working as a network administrator.
>
> Host-based packet filters are usually only used on machines that
> sometimes get connected directly to the Internet (Laptops, usually).
>
> The only other instance of "double-firewalling" I know off in the
> industry is a firewall with a DMZ between two packet filters - not to be
> confused with any "desktop firewall".
>
> "Desktop firewalls" usually are a support nightmare, as they prevent IT
> from doing maintenance on the machines quite often (especially if the
> user managed to screw around with the rules again), and offer no real
> benefit for normal workstations.
Double firewalling (hardware + software) is recommended by US-CERT:
http://www.us-cert.gov/reading_room/HomeComputerSecurity/
http://www.cert.org/homeusers/goalof_computersecurity.html
http://www.us-cert.gov/reading_room/before_you_plug_in.html
|