Go Back   Data Center, Colocation, Cloud Computing, Storage, Dedicated Servers Forums > General DataCenter Discussion Forum > Discuss about Datacenter Software/Hardware Related Issues.

Reply

 

Thread Tools
  #1  
Old 04-24-2008, 06:02 AM
bigdaddy bigdaddy is offline
Junior Member
 
Join Date: Apr 2008
Posts: 1
Smile Firewall or No firewall? please help

I have been assigned to setup some servers in the datacenter... we have two DBs (and may expand to 3) running behind a load balancer to get the best performance and avoid bottleneck when search queries are being done.

We have a DB of about 20 million records... so a lot of searches.

to all DC experts... do you recommend that i do without a firewall or with a firewall. i always thought that if we put in a firewall in front of the web server, the connection (and bottleneck) will slow down tremendously, is this true?

should i put in a Cisco/Netscreen firewall or i can do away with iptables (Linux firewall if you will)?

please advise. thank you! i need to know this asap.

Last edited by bigdaddy; 04-24-2008 at 06:29 AM.
Reply With Quote
  #2  
Old 06-05-2008, 04:05 AM
Blast Blast is offline
Member
 
Join Date: Jun 2008
Posts: 45
Default

I have not seen any deficiency in our own sites from setting up a firewall. I think all you can do to protect your network is better than having downtime due to attacks.
__________________
USA Wants These People
Reply With Quote
  #3  
Old 11-30-2008, 12:16 AM
attagirl attagirl is offline
Senior Member
 
Join Date: Oct 2008
Posts: 117
Default

I have to agree that it would not hurt to put a fire wall on. I think that as Blast said you want to protect your server instead of taking the chance that it will be attacked ad downtime can really hurt most business.
Reply With Quote
  #4  
Old 04-14-2009, 06:30 AM
john1544 john1544 is offline
Member
 
Join Date: Nov 2008
Posts: 30
Default

I think you will have to go with firewall because it will protect your data.I am also using the firewall in our system and i dont think it is affecting speed.
Reply With Quote
  #5  
Old 04-14-2009, 03:24 PM
Schumie Schumie is offline
Senior Member
 
Join Date: Dec 2008
Location: Thatcham, UK
Posts: 160
Send a message via MSN to Schumie
Default

Quote:
Originally Posted by john1544 View Post
I think you will have to go with firewall because it will protect your data.I am also using the firewall in our system and i dont think it is affecting speed.
B$ - a firewall won't protect your data, it will simply restrict access down to your systems.

Depending on your traffic load, you should appropriately size the firewall - for example, if your solution is doing 500,000pps/ A few Gig of traffic don't use a SonicWall TZ170 or Cisco ASA5505 as it will just die under the load

Ensure that you configure the firewall appropriately else it would just as well be used as a door stop to!
Reply With Quote
  #6  
Old 04-14-2009, 05:25 PM
Alexandre Alexandre is offline
Member
 
Join Date: Oct 2008
Posts: 72
Default

I think the same< it would be better to apply a hardware solution.
__________________
HostingZoom webhosting
-------------------------
Power, speed, reliability
Reply With Quote
  #7  
Old 04-15-2009, 08:55 AM
Schumie Schumie is offline
Senior Member
 
Join Date: Dec 2008
Location: Thatcham, UK
Posts: 160
Send a message via MSN to Schumie
Default

Quote:
Originally Posted by Alexandre View Post
I think the same< it would be better to apply a hardware solution.
Oh, defiantly always recommend a hardware firewall - software firewalls always scare the pants out of me purely for the reason that the packets are still getting to the server, and if there is a flaw in the firewall code it could be exploited. While this can happen on a hardware firewall, at least it is physically separate to your servers
Reply With Quote
  #8  
Old 03-05-2010, 04:31 PM
Andrew22 Andrew22 is offline
Junior Member
 
Join Date: Feb 2010
Location: U.K
Posts: 20
Default Firewall or No firewall? please help

I would say to definitely use a firewall. The reasoning about dialup and different IP's has a flaw. The flaw is that if you have a trojan virus running, and no firewall or effective AV program, the trojan virus sits there and opens a port on your computer, and will either send out packets of data basically saying 'here is a wide open computer ripe for exploitation', or opens a port and waits for a incoming data stream. It doesn't matter that there is a different IP each time, this trojan would be broadcasting the current one. Some of these can identify themselves as coming from a specific computer.
The XP firewall does nothing to stop anything from connecting out, a third party firewall can monitor what is connecting out, and can allow or deny access to the internet.
Reply With Quote
  #9  
Old 05-13-2010, 03:44 AM
izumi777 izumi777 is offline
Junior Member
 
Join Date: May 2010
Posts: 12
Default

I agree with Blast. To protect your network is better than having downtime due to attacks.
__________________
Affordable, Reliable Hosting and VPS Solutions
Quality Host Excellent Support
Powered By HOSTNEVERDIE Web Hosting
Reply With Quote
  #10  
Old 05-29-2010, 11:10 AM
Jaflosan Jaflosan is offline
Junior Member
 
Join Date: May 2010
Posts: 4
Default

It's not only OK to use both a hardware firewall and a software firewall, it's recommended. Your hardware firewall provides NAT which separates your network from the internet, and should be checking packets on their way in to make sure they're legitimate. Your software firewall should be checking not only inbound traffic, but also outbound traffic. This is important so that if a rogue application gets installed you should be notified of unusual behavior.
__________________
suchmaschinet | berlin apartment | mannequin
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 10:05 PM.

Member Area



Data Center Industry Daily News


Cloud and Dedicated Hosting


Sponsors Managed Servers Sponsored by DedicatedNOW.
Powered by vBulletin® Version 3.8.9
Copyright ©2000 - 2024, vBulletin Solutions, Inc.