> On Wed, 31 May 2006 01:42:52 GMT 'Craig'
> posted this onto alt.comp.freeware:
>
> [snip]
>
>
>>Mind you, I'm not running a personal firewall atm so...ymmv.
>
>
> Wow! How do you get away with that?
>
[n.b. I wouldn't suggest this for everyone...this is an experiment]
I want to prevent unauthorized access to port addresses and services. I
also want to avoid DoS and "malicious" traffic attacks (eg smurfs,
PoD's, spoofing, SYN floods, etc).
To address these, I've
- rechecked the config of our router's firewall and,
- locked down ports & services not needed on the computer
- continue to run system-wide a/v.
It's taken a few hours of time, by far the most on reading and
re-reading what should & shouldn't be made available on a system. But,
once that's understood, it's pretty easy to do.
All of this applies to desktop systems. For our laptops, we've also run
them through the "hardening process," but we still run ZoneAlarm since
we have no control over most networks when traveling. Which reminds me
of the one thing I miss about ZA on the desktop: Getting alerts on
phone-home apps.