Merit Network
Can't find what you're looking for? Search the Mail Archives.
  About Merit   Services   Network   Resources & Support   Network Research   News   Events   Home

Discussion Communities: Merit Network Email List Archives

North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

RE: FW: Worms versus Bots

  • From: Michel Py
  • Date: Tue May 04 13:34:50 2004

> Smith, Donald wrote:
> The goal of this document is help new XP users
> survive long enough to do their updates.

It is regrettable though that no mention is made of real personal
firewalls such as ZoneAlarm (ICF has no egress control whatsoever).
Although the intentions behind this document are good, I am concerned
that users might get a false sensation of security after reading it
(because after doing some steps it is now "safe" to plug the network).


> Many of them cant/wont put up acls/nat/firewalls...

IMHO there is no excuse not to have a $39 box on a broadband connection.
And, contrary to ICF, it can't be deactivated. Talking about defense in
depth, this box _is_ the first line of defense.

When I install a PC at friends and family, my sequence is:
1. Hardware NAT/router/firewall. Deactivate uPNP and wireless.
2. Passwords
3. Windows Update
4. Office online
5. Norton anti-virus with automatic updates and scheduled scans.
6. ZoneAlarm
7. Ad-aware with update
8. Run a full virus scan
9. Run a full spyware scan

ICF is not even part of the picture as it does not remove the need for
the hardware nor the need for ZoneAlarm. As far as spending money on
hardware, it's part of what is required to have my help, along with beer
and baked goods.

Michel






Discussion Communities


About Merit | Services | Network | Resources & Support | Network Research
News | Events | Contact | Site Map | Merit Network Home


Merit Network, Inc.