Go Back   PCMech Forums > Help & Discussion > Networking & Online Security

Need Some Help? Type Your Keywords Here:

Reply
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
Old 10-18-2004, 03:58 PM   #1
Member (9 bit)
 
Join Date: Jul 1999
Location: Denver
Posts: 395
Need a more advanced firewall - Not Linksys

I currently have a simple Linksys Router/Firewall acting as the gateway for my small LAN. As with all my Linksys products, it works very well for what it does.

Recently, however, I had my ISP bring up a VPN which connects all 5 of my offices together using their routers, equipment, etc. I can ping out from behind my Linksys to all branch offices to specific computers, but I can't ping from a branch office through the WAN side of the Linksys to any computers on the LAN. My ISP insists that its ICMP packets are being blocked at my Linksys firewall, therefore, preventing anyone from my branch offices from "seeing" anything behind the firewall. I'm assuming they're right since I do see log entries on my firewall which tell me that certain ICMP packets are getting dropped because it thinks it's a Smurf Attack. These packets are originating from my ISP's equipment.

Even with Block Unsolicited WAN Requests disabled on the firewall these ICMP packets do not seem to get through.

I'm wondering if I need to upgrade my firewall to something a bit more sophisticated. Something on which I can tell it specifically which IPs to trust for ICMP. If so, what would anyone recommend? I'm not a firewall expert so it would need to be something that was fairly intuative but with more granular control than Linksys.

Any ideas folks?

Thanks
Wanabe
Wanabe is offline   Reply With Quote
Old 10-19-2004, 07:16 AM   #2
I am, in reality, a moose
Staff
Premium Member
 
mbossman2's Avatar
 
Join Date: Aug 1999
Location: RTP, NC
Posts: 2,441
Cisco PIX, Sonicwall, Juniper/Netscreen

All of these are good products.

Specific models will depend on the number of users behind the firewalls and additional features that you would want.
__________________
Veritas Principium Libertas

Traveling Moose

Last edited by mbossman2; 10-19-2004 at 08:07 AM.
mbossman2 is offline   Reply With Quote
Old 10-19-2004, 12:15 PM   #3
Member (9 bit)
 
Join Date: Jul 1999
Location: Denver
Posts: 395
Thanks mbossman2.

I'll look into these.

Wanabe
Wanabe is offline   Reply With Quote
Old 10-19-2004, 02:25 PM   #4
I am, in reality, a moose
Staff
Premium Member
 
mbossman2's Avatar
 
Join Date: Aug 1999
Location: RTP, NC
Posts: 2,441
i can talk in detail to the PIX box if you need help in that direction.
mbossman2 is offline   Reply With Quote
Reply

Bookmarks

Still Need Help? Type Your Keywords Here:


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 01:00 PM.
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.0 PL2