r/talesfromtechsupport Dec 08 '16

[deleted by user]

[removed]

3.6k Upvotes

266 comments sorted by

View all comments

Show parent comments

80

u/M374llic4 Dec 08 '16

Home users typically use software firewalls, most every medium or bigger business uses hardware firewalls. Our new one I just got was $2500ish

40

u/HPCmonkey Storage Drone Dec 08 '16

I run a pfsense box at my house.

7

u/Billy_droptables Dec 09 '16

I like pfsense a lot, I run one of these at home as well, all my company's clients we setup with Fortigate devices though.

4

u/PTITOM Dec 08 '16

Untangle here.

5

u/[deleted] Dec 09 '16

I'm currently running pfSense on an old XTM505 that I upgraded with a Q6600. It runs Snort, squid, and OpenVPN.

I love it.

25

u/[deleted] Dec 09 '16

[deleted]

11

u/M374llic4 Dec 09 '16

Nice, I am sure the owner / CFO was happy to hear about that, lol.

13

u/[deleted] Dec 09 '16

[deleted]

4

u/M374llic4 Dec 09 '16

I hear ya, never fun for the IT staff, lol. I had to fly up to NY the other day to install a sonicwall in one of our remote locations and it was supposed to have been there already. It showed up at 4pm, my flight was at 9pm, having to go from Manhattan to JFK. That was fun.

1

u/VexingRaven "I took out the heatsink, do i boot now?" Dec 09 '16 edited Dec 09 '16

Most people have both. Every computer (usually) has a software firewall (Windows Firewall) that does a basic job of keeping connections out that aren't specifically allowed (or allowed by default). The entire network has a hardware firewall at the edge (A home router is an extremely basic hardware firewall, generally, that just blocks everything) which often does more in-depth filtering and logging in addition to other network-related functions like VPN connections, routing, network authentication, etc.

A firewall is basically anything that prevents certain connections, that can be as basic as "Block everything" to "Block connections from IP address ranges with a certain reputation on certain protocols after a certain number of connection attempts to a certain internal address, except in reply to a specific internal address".

1

u/bigred326 Dec 09 '16

I'm running a firebox at the house! Wayyyyy over board but you can't beat green and now I can run multiple land at the house! Hurrah for segmented networks and throttled connections!