Re: 2 software firewalls simultaneously?



On 2008-04-28, Jolly Roger <jollyroger@xxxxxxxxx> wrote:
In article <lightoflife-2227E8.21553927042008@xxxxxxxxxxxxxxxxx>,
Mike <lightoflife@xxxxxxxxxx> wrote:

Would there be any good reason to run a second firewall alongside
Apple's default firewall? As in using ipfw via Water Roof for instance?

WaterRoof is simply a front end to Apple's firewall, ipfw.

So the question he's asking is, is there any reason to use both the
application-based firewall (ie, the one with the Apple-supplied gui)
and the port-based firewall (ie, ipfw).

The general answer to that is, yes, there's a good reason: these are
fundamentally different approaches to firewalling that protect against
different kinds of security breaches.

On the other hand, if the OP is really just looking for "buttons and
menus", as he says, there's probably no point. Making effective use
of ipfw as another layer of firewall requires some understanding of
how it works. If he doesn't feel comfortable writing his own rules,
he's not likely to add much security to what the application-based
firewall is already providing.



.


Quantcast