Web Host Chat
Bringing Hosts & Customers together since 2001
Home QLinks Members Your Profile Register FAQ's Hosts Only Area SMS Alerts Advertising
User Information
»REGISTER NOW!

Go Back   Web Host Chat > Web Hosting Chat > Networking, Routing and Transit
Reply
 
LinkBack Thread Tools
Old 2nd April 2006   #1 (permalink)
Certified User (52)
Silver Quality
Fresh-Networks's Avatar
Join Date: Jan 2006
Location: Manchester
Age: 26
Posts: 44
Fresh-Networks is on a distinguished road
Talking Does making your a computer a DMZ host make it insecure?

Hey, Just a Fresh question.

I have been experiencing uber slow downloads on My P2P programs and torrent clients on my lean mean p3 downloading machine . And one of them said something about NAT/Firewall settings. So i had a fiddle in my wireless routers control panel (bt voyager 2000) and came across DMZ host, stating:

DMZ Host

A DMZ host is a computer on your network that can be accessed from the Internet regardless of NAT, virtual server and firewall settings.

Setting-up a DMZ host has implication on the security of your network. Only set-up DMZ if you understand the consequences.

Since it said ' Regardless of NAT ' i went ahead

So now i have slightly faster downloads, just dont want my 6 month on the trot non-stop p3 system windows installation dying because of some ex-customer who hate me or something hacking me. :<

(ps only has windows firewall and AVG free)


Kind Regards, Lee.
__________________
Registered User
Fresh-Networks is offline   Reply With Quote
Old 2nd April 2006   #2 (permalink)
I am Staff at
Secura Hosting Ltd
About My Company!


Certified Host
markcastle's Avatar
Join Date: Aug 2002
Location: London, England
Posts: 3,061
markcastle is on a distinguished road
Quote:
Does making your a computer a DMZ host make it insecure?
Wow.. are you serious?
__________________
••• Mark Castle ••• Secura Hosting Ltd •••
••• Managed Hosting •••
••• AS29452UK Company Reg No: 04330657VAT Number: 789 2703 81Sales: 0845 123 2632 •••
My views are my own and not those of my company.
__________________
Web Host - VIP Member
markcastle is online now   Reply With Quote
Old 2nd April 2006   #3 (permalink)
Certified User (52)
Silver Quality
Fresh-Networks's Avatar
Join Date: Jan 2006
Location: Manchester
Age: 26
Posts: 44
Fresh-Networks is on a distinguished road
Yes I never really bothered studying wireless, just there because i dont want to drill holes all around my house for cables :<
__________________
Registered User
Fresh-Networks is offline   Reply With Quote
Old 2nd April 2006   #4 (permalink)
I am Staff at
Mooharr
About My Company!


Certified Host
Join Date: Jun 2003
Posts: 1,702
JamesSykes is on a distinguished road
On most routers you set the private IP address as "DMZ" so it will just forward ALL traffic to you, essentially negating the protection you get from NAT.

It wont MAKE your computer insecure but its not a great idea unless you keep ontop of all your patches/updates to stop yourself getting hacked.
__________________
Mooharr
E-Mail Hosting Services

These are not my views and i cannot be held accountable for anything he says.
__________________
Web Host - VIP Member
JamesSykes is offline   Reply With Quote
Old 2nd April 2006   #5 (permalink)
~ Forum Staff ~
Super Duper Mod


External (not bb dev staff)
Join Date: Mar 2006
Location: Uxbridge, Middlesex.
Posts: 1,218
JSamuel is on a distinguished road
DMZ - DeMilitarised Zone (sp..)
In short - no defenses, pure exposure.
__________________
Joel Samuel
WebHostChat Moderator

Real Hosts Limited | Colocation | VP/Dedicated Servers | Monitoring | Backup | Virtual Hosting

[e] j.samuel@real-hosts.co.uk | [p] 0845 890 5480 | [f] 0845 890 5481

Planet Audio Group | MacUniverse - Apple MacBook MacBook Pro MacPro & X-Serve | Planet Audio | Planet Video
[e] sales@planetaudiosystems.co.uk | [p] 0208 950 1485 | [f] 0208 950 1294

I represent my own views and not those of my companies or the forum(s) on which I moderate.

JSamuel is offline   Reply With Quote
Old 2nd April 2006   #6 (permalink)
I am Staff at
eHosting Limited
About My Company!

Certified Host
Join Date: Oct 2004
Location: Manchester, UK
Posts: 185
PaulC is on a distinguished road
Quote:
Originally Posted by Fresh-Networks
So now i have slightly faster downloads
The faster downloads will more than likely be related to the ports all being forwarded to the download machine by means of the DMZ. The best idea is to remove the DMZ and setup port forwarding for the associated ports to the internal IP of this machine.
__________________
Paul Carter
eHosting Limited
__________________
Web Host - Certified Member
PaulC is offline   Reply With Quote
Old 2nd April 2006   #7 (permalink)
Certified User (52)
Silver Quality
Fresh-Networks's Avatar
Join Date: Jan 2006
Location: Manchester
Age: 26
Posts: 44
Fresh-Networks is on a distinguished road
Ok, Thanks Paul . I just checked and it lets me do a range as my p2p programs vary port to port, some choose random of say: 6453-6568.

Regards, Lee
__________________
Registered User
Fresh-Networks is offline   Reply With Quote
Old 2nd April 2006   #8 (permalink)
Join Date: Nov 2004
Location: London
Posts: 178
Joe is on a distinguished road
It's a silly name for 1:1 nat, and its quite possibly the silliest idea ever, either give the machine a routable ip or don't.
__________________
Joe Holden
Pro-Net Internet Services Limited
__________________
Web Host - Certified Member
Joe is offline   Reply With Quote
Old 2nd April 2006   #9 (permalink)
I am Staff at
Mooharr
About My Company!


Certified Host
Join Date: Jun 2003
Posts: 1,702
JamesSykes is on a distinguished road
It works well for me when i want to play xbox live on my 360
__________________
Mooharr
E-Mail Hosting Services

These are not my views and i cannot be held accountable for anything he says.
__________________
Web Host - VIP Member
JamesSykes is offline   Reply With Quote
Old 3rd April 2006   #10 (permalink)
I am Staff at
Secura Hosting Ltd
About My Company!


Certified Host
markcastle's Avatar
Join Date: Aug 2002
Location: London, England
Posts: 3,061
markcastle is on a distinguished road
If you are going to implement Demilitarized Zones then you really ought to understand what they are
http://searchwebservices.techtarget....213891,00.html

If your firewall is soooo poor that you can't get good speeds through it, i'd suggest that you need to invest in a better firewall rather than rather than make your systems less secure. Consider it similar to putting your TV outside on your driveway... you might pick up a slightly better picture outside but someone is going to steal it sooner or later.
__________________
••• Mark Castle ••• Secura Hosting Ltd •••
••• Managed Hosting •••
••• AS29452UK Company Reg No: 04330657VAT Number: 789 2703 81Sales: 0845 123 2632 •••
My views are my own and not those of my company.
__________________
Web Host - VIP Member
markcastle is online now   Reply With Quote
Old 17th April 2006   #11 (permalink)
I am Staff at
SynergyWorks
About My Company!


Basic Host
SynergyWorks's Avatar
Join Date: Jul 2003
Location: Kent, UK
Posts: 1,416
SynergyWorks is on a distinguished road
Quote:
Originally Posted by markcastle
Consider it similar to putting your TV outside on your driveway... you might pick up a slightly better picture outside but someone is going to steal it sooner or later.
Can we not just put the aerial outside and leave the TV indoors?


... anyway, back on topic.
A DMZ although better if you can live without it, isn't a problem with a windows machine fully patched with a basic firewall. At the office we have an ADSL line with 5 public IPs assigned directly to windows machines running nothing but Windows XP SP2 with the latest patches and windows firewall - never been hacked. *touch wood*


Just my two pence....
__________________
Robert Bentley

SynergyWorks.co.uk - AS41659
Dedicated Servers - Virtual Servers - South East / Kent Colocation & Rackspace - IP Transit
T: +44 (0)1622 808 420 / F: +44 (0)1622 808 422 / E: r.bentley [at] synergyworks.co.uk

VAT #: GB 913 4306 53
__________________
Web Host - VIP Member
SynergyWorks is offline   Reply With Quote
Old 18th April 2006   #12 (permalink)
I am Staff at
Cyberprog New Media
About My Company!


Certified Host
Cyberprog's Avatar
Join Date: Jul 2003
Location: Bristol, UK
Age: 26
Posts: 1,839
Cyberprog is on a distinguished road
I use my routers with what I call and DMZ, except the routers are setup with public addresses on the DMZ, but filter what IP traffic actually gets through to them. Then the LAN side is private only (other than specified NAT translations) and the WAN is the connection to the ADSL network or upstream. Found that works best for us as the firewall centralises everything and you can throw a machine up publicly easily while it being secured by the firewall.
__________________
Alex Threlfall
Cyberprog New Media
www.cyberprog.net
Of course my bull-bar is safe, it sits so high the old people and the children go underneath.
__________________
Web Host - VIP Member
Cyberprog is offline   Reply With Quote
Old 18th April 2006   #13 (permalink)
I am Staff at
Secura Hosting Ltd
About My Company!


Certified Host
markcastle's Avatar
Join Date: Aug 2002
Location: London, England
Posts: 3,061
markcastle is on a distinguished road
Quote:
Originally Posted by SynergyWorks
At the office we have an ADSL line with 5 public IPs assigned directly to windows machines running nothing but Windows XP SP2 with the latest patches and windows firewall - never been hacked. *touch wood*
This is the sort of mentality that i just can't understand though.. it's not like a reasonable hardware firewall will break the bank, strewth you could even use an old PIII 500MHz running ipcop or m0n0wall if you are really skint, then use the software firewalls as last line of defence.

I also can't understand why on earth a hosting company would want to highlight their wide open security policy on a public forum; you must be mad. I hope you don't have any customer data / personal information or passwords on those machines. You'd likely be in breach of the data protection laws if nothing else.
__________________
••• Mark Castle ••• Secura Hosting Ltd •••
••• Managed Hosting •••
••• AS29452UK Company Reg No: 04330657VAT Number: 789 2703 81Sales: 0845 123 2632 •••
My views are my own and not those of my company.
__________________
Web Host - VIP Member
markcastle is online now   Reply With Quote
Old 18th April 2006   #14 (permalink)
I am Staff at
SynergyWorks
About My Company!


Basic Host
SynergyWorks's Avatar
Join Date: Jul 2003
Location: Kent, UK
Posts: 1,416
SynergyWorks is on a distinguished road
Quote:
Originally Posted by markcastle
This is the sort of mentality that i just can't understand though.. it's not like a reasonable hardware firewall will break the bank, strewth you could even use an old PIII 500MHz running ipcop or m0n0wall if you are really skint, then use the software firewalls as last line of defence.

I also can't understand why on earth a hosting company would want to highlight their wide open security policy on a public forum; you must be mad. I hope you don't have any customer data / personal information or passwords on those machines. You'd likely be in breach of the data protection laws if nothing else.
No customer data, and i'd be interested to hear of any known security flaws in the windows firewall & windows file sharing.
__________________
Robert Bentley

SynergyWorks.co.uk - AS41659
Dedicated Servers - Virtual Servers - South East / Kent Colocation & Rackspace - IP Transit
T: +44 (0)1622 808 420 / F: +44 (0)1622 808 422 / E: r.bentley [at] synergyworks.co.uk

VAT #: GB 913 4306 53
__________________
Web Host - VIP Member
SynergyWorks is offline   Reply With Quote
Old 18th April 2006   #15 (permalink)
Trusted User (249)
Platinum User
OliverMargetts's Avatar
Join Date: Sep 2005
Location: Oxfordshire, UK
Posts: 176
OliverMargetts is on a distinguished road
Wow, I don't use NAT, but I've got a FireBrick hardware firewall sat between the internet and everything else. I wouldn't dream of allowing Windows PC's on the network with a public IP without it.

The Windows firewall is one of the most useless bits of junk I've ever seen, too - it's so easy to bypass it's laughable. Perhaps if you used a firewall not built in to the OS, it'd be slightly more secure...
__________________
[size="1"][b]Regards, Oliver Margetts - Managing Director, (url-removed: need 20 posts)
__________________
Registered User
OliverMargetts is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is Off
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
[NEWS] Young Entrepreneur Making Over $1000 Per Day With A Simplistic Yet ... - Emediawire (press release) [NEWS] Hosting and Tech News 1 10th March 2006 02:20 PM
Your computer? Solvaut General Chit Chat & Discussion 49 20th July 2005 06:31 PM
YOUR COMPUTER IS AT RISK!!! Andrew General Chit Chat & Discussion 1 11th September 2002 12:25 PM


Some great companies!


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0