# Routers

**URL:** <https://boards.straightdope.com/t/routers/195769>\
**Category:** Factual Questions\
**Created:** [August 17, 2003, 1:49pm UTC](https://boards.straightdope.com/t/routers/195769 "2003-08-17T13:49:38Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![ReuvenB](https://avatars.discourse-cdn.com/v4/letter/r/9fc348/32.png) [@ReuvenB](https://boards.straightdope.com/u/ReuvenB)\
**Post date:** [August 17, 2003, 1:49pm UTC](https://boards.straightdope.com/t/routers/195769/1 "2003-08-17T13:49:38Z")

</div>

My computer currently runs through a wireless linksys router. I’ve heard that routers provide protection against accessing my PC remotely (such as the msblaster worm). Is it necessary to also install ZoneAlarm, or is the router enough?

---

<div class="post-metadata">

**Author:** ![Quartz](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/quartz/32/267_2.png) [@Quartz](https://boards.straightdope.com/u/Quartz)\
**Post date:** [August 17, 2003, 1:59pm UTC](https://boards.straightdope.com/t/routers/195769/2 "2003-08-17T13:59:08Z")

</div>

Never mind msblaster, you need a firewall.

---

<div class="post-metadata">

**Author:** ![MC\_Master\_of\_Ceremonies](https://avatars.discourse-cdn.com/v4/letter/m/bb73d2/32.png) [@MC\_Master\_of\_Ceremonies](https://boards.straightdope.com/u/MC_Master_of_Ceremonies)\
**Post date:** [August 17, 2003, 2:01pm UTC](https://boards.straightdope.com/t/routers/195769/3 "2003-08-17T14:01:26Z")

</div>

Yes, everybody (though perhaps not if you’ve only got a dial-up modem) needs a firewall.

---

<div class="post-metadata">

**Author:** ![gazpacho](https://avatars.discourse-cdn.com/v4/letter/g/6f9a4e/32.png) [@gazpacho](https://boards.straightdope.com/u/gazpacho)\
**Post date:** [August 17, 2003, 2:08pm UTC](https://boards.straightdope.com/t/routers/195769/4 "2003-08-17T14:08:13Z")

</div>

All the linksys router boxes I know of are also firewalls. XWalrus2 which linksys box do you have?

---

<div class="post-metadata">

**Author:** ![ReuvenB](https://avatars.discourse-cdn.com/v4/letter/r/9fc348/32.png) [@ReuvenB](https://boards.straightdope.com/u/ReuvenB)\
**Post date:** [August 17, 2003, 2:13pm UTC](https://boards.straightdope.com/t/routers/195769/5 "2003-08-17T14:13:59Z")

</div>

It’s the wireless access point, model BEF11S4.

---

<div class="post-metadata">

**Author:** ![Quartz](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/quartz/32/267_2.png) [@Quartz](https://boards.straightdope.com/u/Quartz)\
**Post date:** [August 17, 2003, 2:26pm UTC](https://boards.straightdope.com/t/routers/195769/6 "2003-08-17T14:26:30Z")

</div>

Beware! NAT is not a firewall.

---

<div class="post-metadata">

**Author:** ![dead0man](https://avatars.discourse-cdn.com/v4/letter/d/edb3f5/32.png) [@dead0man](https://boards.straightdope.com/u/dead0man)\
**Post date:** [August 17, 2003, 3:41pm UTC](https://boards.straightdope.com/t/routers/195769/7 "2003-08-17T15:41:16Z")

</div>

[BEF11S4](http://www.linksys.com/Products/product.asp?grid=33&scid=35&prid=415)

> [@](#):
>
> Configurable as a DHCP server for your existing network, the Wireless Access Point Router with 4-Port Switch acts as the only externally recognized Internet gateway on your local area network (LAN) and serve as an Internet NAT firewall against unwanted outside intruders.

I have a non-wireless linksys router. Before that, I used zonealarm and got pretty much constantly bombarded with internet noise and the occasional bad guy. After I got the router, zonealarm stopped getting these hits, completely. I don’t have zonealarm running on any of my computers (even one that’s in the DMZ for gaming reasons), and I have never had a problem.

---

<div class="post-metadata">

**Author:** ![dead0man](https://avatars.discourse-cdn.com/v4/letter/d/edb3f5/32.png) [@dead0man](https://boards.straightdope.com/u/dead0man)\
**Post date:** [August 17, 2003, 3:43pm UTC](https://boards.straightdope.com/t/routers/195769/8 "2003-08-17T15:43:04Z")

</div>

…and to answer your question 🙂  
No you don’t need a software firewall because you allready have a better hardware firewall. Just make sure you change the password on your router.

---

<div class="post-metadata">

**Author:** ![Jake4](https://avatars.discourse-cdn.com/v4/letter/j/bc8723/32.png) [@Jake4](https://boards.straightdope.com/u/Jake4)\
**Post date:** [August 17, 2003, 4:01pm UTC](https://boards.straightdope.com/t/routers/195769/9 "2003-08-17T16:01:27Z")

</div>

> [@](#):
>
> \*Originally posted by MC Master of Ceremonies \*  
> \*\*Yes, everybody (though perhaps not if you’ve only got a dial-up modem) needs a firewall. \*\*

I disagree. Everybody needs a firewall.

I’m on dial-up, and thought my university’s built-in protection would protect me, so stupidly ignored my home (dial-up) computer’s security, while keeping my work computers & laptop up to date w/all anti-virus, firewall, and windows updates.

Guess which worm I was infected with yesterday?

Guess how quickly I patched my computer and DLed ZoneAlarm? PDQ, that’s how quick.

And to “Me too” a little, your router provides hardware firewall protection, which is better than software, as long as everything is up-to-date and configured correctly. But there is no reason not to add a software firewall anyway. You might not ‘need’ one, but…

---

<div class="post-metadata">

**Author:** ![da\_pope](https://avatars.discourse-cdn.com/v4/letter/d/7ba0ec/32.png) [@da\_pope](https://boards.straightdope.com/u/da_pope)\
**Post date:** [August 17, 2003, 4:11pm UTC](https://boards.straightdope.com/t/routers/195769/10 "2003-08-17T16:11:47Z")

</div>

No, NAT is technically not a firewall, but the linksys and netgear (and probably most other home router/switches) show up as all ports stealthed on the public side. A port will only pass traffic if it was requested from the inside, otherwise no ports will respond. That’s a GOOD thing.

This also makes a very good case for a software firewall like zonealarm, as it will now tell you if something on your computer is attempting to access the internet, which the linksys/netgear would ALLOW by default.

Unless you had specific ports on the linksys forwarded to a host (pc) on your inside network, which is kind of advanced and not set like that by default, you’ll avoid any crap like the recent RPC overflow exploit.

In other words, use the linksys to protect from random (or targeted) outside activity coming in, and use zonealarm to prevent malicious spyware, crapware etc… from accessing the internet from the inside.

Also don’t forget to patch early and often.
