Firewall Tests Lower after Adding DSL Modem/Router

Firewall Tests Lower after Adding DSL Modem/Router

Secure Home | Search | About

Networking Firewalls - Software and hardware firewalls discussions 

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
Firewall Tests Lower after Adding DSL Modem/Router JB 07-25-2006
Posted by JB on July 25, 2006, 5:20 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Until yesterday I was using dialup with the Norton Internet package and
getting "perfect" firewall test results from Gibson's "Shield Up" site.

I added a Zoom X5 dsl modem/router and the test results now show most ports
blocked but not stealthed.

The modem is running in the dyanamic NAT mode which is the same as NAPT.


Any idea as to why my test results show the system less secure with the
router than without it?

Thank you,

Mike



Posted by Sebastian Gottschalk on July 25, 2006, 6:08 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
JB wrote:
> Until yesterday I was using dialup with the Norton Internet package and
> getting "perfect" firewall test results from Gibson's "Shield Up" site.

OK, you've got a lot of fun with playing with toys.

> I added a Zoom X5 dsl modem/router and the test results now show most ports
> blocked but not stealthed.

Yes, that's pretty good. However, it would be better to have selective
access to this default behaviour.

> Any idea as to why my test results show the system less secure with the
> router than without it?

Huh? Why should it be less secure? And how should something be less
secure than your toys?

Posted by Ansgar -59cobalt- Wiechers on July 25, 2006, 6:50 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
JB wrote:
> Until yesterday I was using dialup with the Norton Internet package
> and getting "perfect" firewall test results from Gibson's "Shield Up"
> site.
>
> I added a Zoom X5 dsl modem/router and the test results now show most
> ports blocked but not stealthed.

"Stealth" is just ridiculous marketing bullshit. Your computer isn't
invisible just because you don't respond to incoming packets. If there's
no computer then the last router *before* it will respond e.g. with a
"destination unreachable" ICMP packet. No response usually means "yes,
there *is* a host, and it's dropping packets".

[...]
> Any idea as to why my test results show the system less secure with
> the router than without it?

Your system isn't less secure.

cu
59cobalt
--
"All vulnerabilities deserve a public fear period prior to patches
becoming available."
--Jason Coombs on Bugtraq

Posted by Duane Arnold on July 26, 2006, 1:54 am
If you were  Registered and logged in, you could reply and use other advanced thread options

> Until yesterday I was using dialup with the Norton Internet package and
> getting "perfect" firewall test results from Gibson's "Shield Up" site.
>
> I added a Zoom X5 dsl modem/router and the test results now show most
> ports blocked but not stealthed.

The machines are behind a NAT router. So, since no unsolicited inbound
traffic can reach the machines and make the machines or the personal FW on
the machines react because the router is setting in front of them blocking
all unsolicited inbound traffic, which is what Gibson's little ridiculous
*stealth* test is about that is reacting to unsolicited inbound traffic to a
machine with a PFW, how are the machines not stealthed?
>
> The modem is running in the dyanamic NAT mode which is the same as NAPT.
>
>
> Any idea as to why my test results show the system less secure with the
> router than without it?

That's because stealth is ridiculous and its a Gibson term. And what do you
mean most ports are blocked and not stealthed? Either all the ports are
closed /blocked on the router or they are not. What is it?

Duane :)



Posted by JB on July 26, 2006, 5:33 am
If you were  Registered and logged in, you could reply and use other advanced thread options

>
>> Until yesterday I was using dialup with the Norton Internet package and
>> getting "perfect" firewall test results from Gibson's "Shield Up" site.
>>
>> I added a Zoom X5 dsl modem/router and the test results now show most
>> ports blocked but not stealthed.
>
> The machines are behind a NAT router. So, since no unsolicited inbound
> traffic can reach the machines and make the machines or the personal FW
> on the machines react because the router is setting in front of them
> blocking all unsolicited inbound traffic, which is what Gibson's little
> ridiculous *stealth* test is about that is reacting to unsolicited inbound
> traffic to a machine with a PFW, how are the machines not stealthed?
>>
>> The modem is running in the dyanamic NAT mode which is the same as NAPT.
>>
>>
>> Any idea as to why my test results show the system less secure with the
>> router than without it?
>
> That's because stealth is ridiculous and its a Gibson term. And what do
> you mean most ports are blocked and not stealthed? Either all the ports
> are closed /blocked on the router or they are not. What is it?
>
> Duane :) <



By blocked and not stealthed I mean that the ports are closed but they
respond to a ping whereas the stealthed ports do not.

Perhaps these tests are only intended for software firewalls. Anyway
here's what I get from Gibson's test of all common ports:

Stealthed ports: 21,23,80,254,255
Closed: All others tested
Open: none

At the Shieldcheck.com site I get this:
Stealthed: 21,23,80,135,139
Closed: All others tested
Open: none


Is there a better test available at a trustworthy site?




>
>



Similar ThreadsPosted
Firewall Tests March 24, 2005, 5:24 pm
adding new ip range to fw-1 March 24, 2005, 4:18 pm
adding IP2 to IPCOP December 11, 2006, 11:46 am
Allow printing traffic from DMZ(Lower Security interface) to inside network on PIX 515E December 8, 2005, 2:53 pm
Leak Tests March 10, 2006, 10:28 pm
adding a network - nokia+checkpoint April 5, 2005, 1:58 pm
System firewalls - comparison, tests...? June 9, 2008, 6:22 am
Kerio 2.1.5 adding posts to block "virus flood" August 17, 2005, 7:50 pm
Norton 2005 Internet Worm Protection (Firewall) or Windows XP native firewall? December 11, 2004, 11:19 am
[Newbie alert!] Is the Linksys BEFSX41 hardware Firewall/router a "real" firewall? March 25, 2005, 11:12 am

The site map in XML format XML site map

Contact Us | Privacy Policy