Quote:
Originally Posted by Sephiroth
If you're gonna have a hardware firewall, don't have it running in the wretched SH. Use modem mode, get a decent router with a well reviewed firewall and use that.
I appreciate that some users can't deploy a firewall in all their end user devices. If they can, (like McAfee, etc), then do that have firewall switched off in front end equipment.
|
or setup a IDPS system using Linux/Snort in between the SH (if running in modem only mode) and your LAN and sniff all packets and drop anything suspicious.