|
Edited on Sat Mar-13-04 05:43 PM by HypnoToad
I've upgraded the firmware of my hardware firewall.
It still thinks everything is smurfy. Meanwhile, the Nortin Internet Security software firewall still gets 'invalid TCP options' attacks from numerous sites. These attacks NEVER ONCE HAPPENED before buying the hardware firewall. And I've had my setup going for a month now.
I talked to sales staff at Best Buy. He said to look in the firmware setup to ensure SPI is enabled. It is enabled by default for Netgear products, but isn't for Linksys products. (Well, that's nice and true and all, but that doesn't answer my question, but I checked anyway, despite being half-sure I never saw what he'd said: The Linksys firewall truly has no option to enable or disable SPI.)
I then went to CompUSA and talked to sales staff at CompUSA. The guy thinks I'm overreacting, but he's saying there isn't a problem either. He also said he was new to networking, so I refuse to take what little he had said seriously. But as long as things cost money, there is a problem. Problem didn't exist before new component. Problem occurs after new component is installed. If you ask me, new component is causing problem.
Norton also seems to record far, far more dropped TCP packets than the Linksys firewall... Per one hardware firewall packet that's logged as dropped do I get 100 of these from Norton:
TCP non-syn/non-ack packet on invalid connection. Packet has been dropped Source IP address: www.google.com(216.239.39.104) Destination IP address: winbloat_emul8r(192.168.1.100) TCP Source Port: http(80) TCP Destination Port: 2619 TCP Message Flags: 0x00000018
Before 3/11, most of my logs are empty.
I think my hardware firewall is rubbish, creating far more problems and resolving nothing. Do you agree?
And should I stick to norton software firewall and not use a h/w firewall?
Thx!
|