Kitz ADSL Broadband Information
adsl spacer  
Support this site
Home Broadband ISPs Tech Routers Wiki Forum
 
     
   Compare ISP   Rate your ISP
   Glossary   Glossary
 
Please login or register.

Login with username, password and session length
Advanced search  

News:

Author Topic: Router firewall rules  (Read 2073 times)

sevenlayermuddle

  • Helpful
  • Addicted Kitizen
  • *
  • Posts: 5369
Router firewall rules
« on: April 16, 2013, 12:08:34 PM »

The day may be close when I'll need to open a firewall port, so that a distant colleague can access a particular service.  This thought fills me with dread as by my reasoning, no matter how tightly I secure my server, it allows the bad guys to easily get malicious data packets into the server's kernel and processes, where some unknown buffer overflow (or other) vulnerability may lurk.

I see my DG834GT seems to allow me to open a very slight crack in my firewall, but still restricted to just a single remote IP.  That would let me sleep better,  I think.  But feel free to disillusion me if I'm missing some other hazards...?

But now my real question... Is the DG834GT's 'single IP' firewall rule common to most routers?  The DG834GT may one day need to be replaced, in which case I'd like to think I can continue to operate the same rule with a new router.
Logged

burakkucat

  • Respected
  • Senior Kitizen
  • *
  • Posts: 38300
  • Over the Rainbow Bridge
    • The ELRepo Project
Re: Router firewall rules
« Reply #1 on: April 16, 2013, 05:18:06 PM »

Any quality modem/router with an in-built firewall should have the ability to restrict access through the firewall to one specific source IP address.
Logged
:cat:  100% Linux and, previously, Unix. Co-founder of the ELRepo Project.

Please consider making a donation to support the running of this site.

sevenlayermuddle

  • Helpful
  • Addicted Kitizen
  • *
  • Posts: 5369
Re: Router firewall rules
« Reply #2 on: April 16, 2013, 06:25:04 PM »

Any quality modem/router with an in-built firewall should have the ability to restrict access through the firewall to one specific source IP address.

That is the reassurance I was seeking, many thanks!
Logged
 

anything