# Two software firewalls overkill?

**URL:** <https://boards.straightdope.com/t/two-software-firewalls-overkill/332173>\
**Category:** Factual Questions\
**Created:** [November 22, 2005, 12:00am UTC](https://boards.straightdope.com/t/two-software-firewalls-overkill/332173 "2005-11-22T00:00:06Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![KlondikeGeoff](https://avatars.discourse-cdn.com/v4/letter/k/3e96dc/32.png) [@KlondikeGeoff](https://boards.straightdope.com/u/KlondikeGeoff)\
**Post date:** [November 22, 2005, 12:00am UTC](https://boards.straightdope.com/t/two-software-firewalls-overkill/332173/1 "2005-11-22T00:00:06Z")

</div>

Have used ZoneAlarm for some time. Recently changed from dialup to cable, so have a router as hardware firewall too.

Also recently changed antivirus program to TrlendMicro’s PC-cillin. It has, among other things, a firewall that can be turned on or not. I tried it, and don’t see any conflicts, but am wondering if that and ZoneAlarm together makes any sense.

Will one do something the other won’t in preventing intrusion, or is it just redundancy?

---

<div class="post-metadata">

**Author:** ![Jayrot](https://avatars.discourse-cdn.com/v4/letter/j/3ec8ea/32.png) [@Jayrot](https://boards.straightdope.com/u/Jayrot)\
**Post date:** [November 22, 2005, 12:10am UTC](https://boards.straightdope.com/t/two-software-firewalls-overkill/332173/2 "2005-11-22T00:10:08Z")

</div>

No, it’s just redundancy (and can cause conflict from time to time, though that’s more common with running 2 anti-viruses at once). Furthermore, the hardware firewall is usally more than sufficient. The only thing you really get from a software firewall like Zonealarm is protection from an infection YOU ALREADY HAVE that’s trying to dial out. It won’t do anything for the incoming intrusions. THe other thing it could possibly protect against is if someone were to plug in an infected machine to your network behind the router’s firewall.

Many people (myself included) don’t use any software firewall at all but rather just maintain safe computing habits and do antivirus scans regularly.

---

<div class="post-metadata">

**Author:** ![Southessex](https://avatars.discourse-cdn.com/v4/letter/s/a3d4f5/32.png) [@Southessex](https://boards.straightdope.com/u/Southessex)\
**Post date:** [November 22, 2005, 5:02am UTC](https://boards.straightdope.com/t/two-software-firewalls-overkill/332173/3 "2005-11-22T05:02:34Z")

</div>

So you have _three_ firewalls in place - one hardware and two software? That’s total overkill, man. You’re wasting system resources and CPU cycles - the additional software firewall just isn’t worth it.

---

<div class="post-metadata">

**Author:** ![Bongmaster](https://avatars.discourse-cdn.com/v4/letter/b/6a8cbe/32.png) [@Bongmaster](https://boards.straightdope.com/u/Bongmaster)\
**Post date:** [November 23, 2005, 4:34pm UTC](https://boards.straightdope.com/t/two-software-firewalls-overkill/332173/4 "2005-11-23T16:34:29Z")

</div>

Another vote that one is sufficient. Pick the one you like best, get rid of the rest. it will only cause problems to have more than one running.

---

<div class="post-metadata">

**Author:** ![Jayrot](https://avatars.discourse-cdn.com/v4/letter/j/3ec8ea/32.png) [@Jayrot](https://boards.straightdope.com/u/Jayrot)\
**Post date:** [November 23, 2005, 4:41pm UTC](https://boards.straightdope.com/t/two-software-firewalls-overkill/332173/5 "2005-11-23T16:41:01Z")

</div>

I’d have to disagree there, Master Bong.

Just use the hardware firewall (i.e. the router). NAT routers are far superior to software firewalls (ehh, for one thing, a nasty virus can’t just turn them off!). As I mentioned above, the only preventative advantage to having a software firewall behind a router is if, say, you had a kid on your local network who may be infecting himself (p2p downloading?).

---

<div class="post-metadata">

**Author:** ![Futile\_Gesture](https://avatars.discourse-cdn.com/v4/letter/f/f05b48/32.png) [@Futile\_Gesture](https://boards.straightdope.com/u/Futile_Gesture)\
**Post date:** [November 23, 2005, 4:48pm UTC](https://boards.straightdope.com/t/two-software-firewalls-overkill/332173/6 "2005-11-23T16:48:44Z")

</div>

I keep a software firewall as well as the hardware one on my router because it can tell me what _software_ is sending (or attempting to send) the traffic. The router doesn’t know and doesn’t care.

---

<div class="post-metadata">

**Author:** ![The\_Shroud](https://avatars.discourse-cdn.com/v4/letter/t/439d5e/32.png) [@The\_Shroud](https://boards.straightdope.com/u/The_Shroud)\
**Post date:** [November 23, 2005, 4:57pm UTC](https://boards.straightdope.com/t/two-software-firewalls-overkill/332173/7 "2005-11-23T16:57:37Z")

</div>

I’m sure my router is sufficient, but I also run [Sygate](http://soho.sygate.com/products/spf_standard.htm), mostly to control which applications “phone home” over the net. I’m always surprised how many non-Internet applications want to access the Internet, even when I’ve turned off auto-update options and such.

---

<div class="post-metadata">

**Author:** ![KlondikeGeoff](https://avatars.discourse-cdn.com/v4/letter/k/3e96dc/32.png) [@KlondikeGeoff](https://boards.straightdope.com/u/KlondikeGeoff)\
**Post date:** [November 23, 2005, 5:02pm UTC](https://boards.straightdope.com/t/two-software-firewalls-overkill/332173/8 "2005-11-23T17:02:57Z")

</div>

Thanks, all, for the info. There does seem to be a bit of disagreement about using a software firewall in addition to the router, and as can’t see any problem with it, will continue with ZoneAlarm, but have turned off the antivirus one. Going with the old belt-and-suspenders policy. 🙂

---

<div class="post-metadata">

**Author:** ![PatriotX](https://avatars.discourse-cdn.com/v4/letter/p/c4cdca/32.png) [@PatriotX](https://boards.straightdope.com/u/PatriotX)\
**Post date:** [November 23, 2005, 5:09pm UTC](https://boards.straightdope.com/t/two-software-firewalls-overkill/332173/9 "2005-11-23T17:09:52Z")

</div>

I’ve never been happy w/ Zone Alarm’s reporting - it always tells me a prog was trying to connect to my DNS. Further, free ZA doesn’t allow for rules configuration.

Hardware is good for keeping people out but donesn’t work so well for keeping baddies who’re already in from calling home. That’s what the software one is better for. Plus they can provide useful logging and other services.

I recommend Sygate.

---

<div class="post-metadata">

**Author:** ![Jayrot](https://avatars.discourse-cdn.com/v4/letter/j/3ec8ea/32.png) [@Jayrot](https://boards.straightdope.com/u/Jayrot)\
**Post date:** [November 23, 2005, 5:51pm UTC](https://boards.straightdope.com/t/two-software-firewalls-overkill/332173/10 "2005-11-23T17:51:41Z")

</div>

OK, I’ll agree with the above, but my point (or is it a sermon?) is that you’re far far better off just practicing safe computing, than relying on a software firewall. (not saying you are, I’m just pontificating).

Indeed, a software firewall will tell you which programs are accessing the internet. Fine. Either they’re:

a) phoning home to report on what you’re doing, in which case it’s spyware and you shouldn’t have gotten it in the first place (safe computing!) and should be caught by regular spyware scans (you should be doing this anyway, regardless of firewalls) or

b) it’s a program automatically updating / checking for updates, which you want. On Windows machines, it’s very important to keep as many of your programs as up to date as possible.

FACT: it is relatively trivial for a virus to disable a software firewall.

However, it’s certainly not bad to have a software firewall in addition to your router. I’ll second the recommendation for Sygate over Zonealarm. Less bloat.
