Which Firewall?

For home users and small office users, firewalls come in a couple of basic flavors. The first is a software firewall which filters (and controls) traffic entering or leaving a single computer. Software firewalls are programs that monitor the ports connecting your computer to others. The second is a network (hardware) firewall, usually a router that several computers use to connect to the web and each other.

If you're a home user with a single PC hooked up directly to the web, you need a software firewall. Windows XP has a fine firewall, though somewhat featureless, which is perfectly adequate for many. If you need something more, ZoneAlarm has a great free firewall (we'll cover both here).

Routers as Firewalls

Many of you will find your computers connected to a router. If you signed up for wireless from your ISP (internet service provider) or bought a router to connect more than one computer to one internet connection, you're behind a firewall. Most routers have programable firewall features, usually set as defaults. Programming routers is a bit beyond this tutorial, but know that if you are behind a router, a software firewall is not absolutely necessary. The exception to this is if you are on a wireless network, but I'll go into that later.

Running Wireless

If you're on a wireless connection to access the internet, you need to be running a software firewall on your computer. Wireless access is inherently more insecure. Because wireless routers and network cards (aka NICs) broadcast and receive signals, any computer within range can also receive these signals. As such, they can see your computer, too, so you need to have a firewall up and going on any computer that's on a wireless network. If your home or SOHO network is hard-wired with CAT-5 cables, accessing and intercepting network packets (signals) is not possible without physically connecting a CAT-5 cable. So again, if you are running wireless, make sure a firewall is up and running on your computer itself. See the right sidebar for more info on securing a wireless network itself.

Open Directory Project at dmoz.org