The Notebook Review forums were hosted by TechTarget, who shut down them down on January 31, 2022. This static read-only archive was pulled by NBR forum users between January 20 and January 31, 2022, in an effort to make sure that the valuable technical information that had been posted on the forums is preserved. For current discussions, many NBR forum users moved over to NotebookTalk.net after the shutdown.
Problems? See this thread at archive.org.

    modem/router firewall question - mine are disabled by default, should i turn them on?

    Discussion in 'Networking and Wireless' started by Tinderbox (UK), Aug 25, 2014.

  1. Tinderbox (UK)

    Tinderbox (UK) BAKED BEAN KING

    Reputations:
    4,740
    Messages:
    8,513
    Likes Received:
    3,823
    Trophy Points:
    431
    Ok

    I have an "TP-LINK's Archer D7 AC1750" which is an adsl modem router, but i am only using it as a router with my fiber modem connected to the lan4/wan port and it works fine.

    But in the setting it has 3 firewalls, one named just firewall, another named ipv6 firewall and the last is called spi firewall and they are all disabled by default.

    Ok, i have used the shields up website and did the extensive ports test and it says all my ports are stealthed.

    Lastly i have Kaspersky IS 2014 and it has it`s own firewall.

    Do i need to enable any of the modem/routers firewalls ???

    Thanks

    John.
     
  2. downloads

    downloads No, Dee Dee, no! Super Moderator

    Reputations:
    7,729
    Messages:
    8,722
    Likes Received:
    2,230
    Trophy Points:
    331
    SPI firewall is always useful. You can also enable ICMP-flood, UDP-flood and TCP-SYN flood protection (you have to have traffic statistics enabled for those to work though).
     
  3. Tinderbox (UK)

    Tinderbox (UK) BAKED BEAN KING

    Reputations:
    4,740
    Messages:
    8,513
    Likes Received:
    3,823
    Trophy Points:
    431
    I have enabled spi firewall, i have turned on traffic statistics but i cannot find "ICMP-flood, UDP-flood and TCP-SYN flood protection" does my model have it?

    Thanks

    John.
     
  4. downloads

    downloads No, Dee Dee, no! Super Moderator

    Reputations:
    7,729
    Messages:
    8,722
    Likes Received:
    2,230
    Trophy Points:
    331
    That's odd, but you are right - there are no setting for it in this particular device. All others TP-Links I've seen so far had those available. I guess the difference in firmware might be due to completely different hardware used - most TP-Links use Atheros chips and I assume yours is based on Broadcom (although I haven't been able to verify it).

    Either way -SPI firewall is a good thing. You can configure it to protect all devices on the network, not only those that have their own software firewalls (tablets and smart-phones would benefit indirectly).

    Also hardware firewall while less flexible than a software one is quite useful as it stops hundreds or thousands of packets that would otherwise be stopped by your software firewall. The latter would start using more and more RAM as a result and traffic/protection statistics would become useless (it would show something like "attacks stopped 16479" most of which would not be even remotely dangerous but your wouldn't be able to sopt any dangerous ones in this flood).

    I used to have a USB ADSL modem for a while and it had no SPI so everything went straight to my software firewall - boy did that look ridiculous when you opened stats :rolleyes:
     
    Tinderbox (UK) likes this.