GOOD Firewall

Got a feature request? Great! Post your ideas here!
dondavis007
Posts: 43
youtube meble na wymiar Warszawa
Joined: Fri Aug 30, 2013 11:19 pm

Re: GOOD Firewall

Post by dondavis007 »

Off cource it's good to have a good firewall in the nas, most people don't have a Juniper or piece of a Clavister Wolf series at home :)
What I can see this OS just have port forwarder and an auto block, you can't use anything more advanced on the osi-layer that I know of?

I'll also say that it's good to have a good firewall behind even a hardware firewall, if you running it in a bigger environment or just don't want your brother trying to hack your old software :)
User avatar
orion
Posts: 3485
Joined: Wed May 29, 2013 11:09 am

Re: GOOD Firewall

Post by orion »

dondavis007 wrote:Off cource it's good to have a good firewall in the nas, most people don't have a Juniper or piece of a Clavister Wolf series at home :)
What I can see this OS just have port forwarder and an auto block, you can't use anything more advanced on the osi-layer that I know of?

I'll also say that it's good to have a good firewall behind even a hardware firewall, if you running it in a bigger environment or just don't want your brother trying to hack your old software :)
Agree with your opinions. +1
ho66es
Posts: 476
Joined: Wed Mar 13, 2013 5:38 am

Re: GOOD Firewall

Post by ho66es »

dondavis007 wrote:Off cource it's good to have a good firewall in the nas, most people don't have a Juniper or piece of a Clavister Wolf series at home :)
What I can see this OS just have port forwarder and an auto block, you can't use anything more advanced on the osi-layer that I know of?

I'll also say that it's good to have a good firewall behind even a hardware firewall, if you running it in a bigger environment or just don't want your brother trying to hack your old software :)
I'm not saying there is no need for a firewall on the NAS, but if you need to block certain ports from the internet I have to ask why the internet has access to those ports in the first place. I do not believe any NAS is designed to sit on the internet but on a lan. and that in my opinion that lan should be firewalled from the internet and only relevant ports exposed. If I want to run a webserver on my NAS I would open port 80 and forward to the NAS and only port 80. Therefore the NAS does not need to block any other port as the internet has no access to them. In a domestic environment a basic firewall on an openwrt or ddwrt router is probably ample if care is taken in network configuration. Investing in a bespoke firewall on the NAS like AV on the NAS could lead end users into a false sense of security especially if they use upnp. There is nothing wrong with having everything firewalled if it is done right, it is just that for most users it could end up causing problems and a false sense of security and a lot of work, a properly crafted firewall is a thing of beauty, a badly crafted one is a disaster waiting to happen :) and I have more than my share of disasters which is why I would rather have it as an app that is an option to install for those that believe they need it and are willing to spend time configuring it and learning how to use it.
608t
buhuhu
Posts: 120
Joined: Mon Oct 07, 2013 3:33 am

Re: GOOD Firewall

Post by buhuhu »

ho66es wrote:
dondavis007 wrote:Off cource it's good to have a good firewall in the nas, most people don't have a Juniper or piece of a Clavister Wolf series at home :)
What I can see this OS just have port forwarder and an auto block, you can't use anything more advanced on the osi-layer that I know of?

I'll also say that it's good to have a good firewall behind even a hardware firewall, if you running it in a bigger environment or just don't want your brother trying to hack your old software :)
I'm not saying there is no need for a firewall on the NAS, but if you need to block certain ports from the internet I have to ask why the internet has access to those ports in the first place. I do not believe any NAS is designed to sit on the internet but on a lan. and that in my opinion that lan should be firewalled from the internet and only relevant ports exposed. If I want to run a webserver on my NAS I would open port 80 and forward to the NAS and only port 80. Therefore the NAS does not need to block any other port as the internet has no access to them. In a domestic environment a basic firewall on an openwrt or ddwrt router is probably ample if care is taken in network configuration. Investing in a bespoke firewall on the NAS like AV on the NAS could lead end users into a false sense of security especially if they use upnp. There is nothing wrong with having everything firewalled if it is done right, it is just that for most users it could end up causing problems and a false sense of security and a lot of work, a properly crafted firewall is a thing of beauty, a badly crafted one is a disaster waiting to happen :) and I have more than my share of disasters which is why I would rather have it as an app that is an option to install for those that believe they need it and are willing to spend time configuring it and learning how to use it.

What happen when you buy a NAS for company not for home and you want to use for disaster recover ?? That NAS must be in internet with public IP.

NAS it is not JUST FOR HOME multimedia, pictures......we need VPN server, ldap server, firewall, samba with active directory build in auth etc.....

Course ASUSTOR it is a new company but they must to be different like other, not just copy from other.. In my opinion it is not need to have many application, it is need to leave possibility to let user to install EASY any app with YUM or APT-GET or PKG_ADD or any tools want.

When you buy a NAS ~75% of the price is software not hardware and normal to have some requirements from producer.

Regards,
ho66es
Posts: 476
Joined: Wed Mar 13, 2013 5:38 am

Re: GOOD Firewall

Post by ho66es »

maybe they need to have two tiers of nas software, pro and domestic, so one flavour without the multimedia software but with fully hardened os and apps, and another a multimedia version. I just don't think it is possible to have a one solution approach to so many angles and I think the nas may suffer as a result.

even if most components are available as apps I fear users will install them all and the risk of conflicts is scary. The problem with a lot of the secure business type applications wanted is they are normally deeply embedded in the os and probably not suited to being apps and therefore not a choice.

I have yet to see a budget server in business that handles so many tasks in one low power package, there may be a reason for that. Or I am wrong and asustor will produce miracles. If I wanted to buy a nas for business disaster recovery, I am sorry but it would in all likelihood not be asustor, qnap, or synology, more likely a bespoke dell server(s) with all the addons required.

But hey you have your opinions and I have mine, it is obvious we think differently about this and I hope asustor is able to satisfy differing sets of needs :)

I am out of this thread
608t
dondavis007
Posts: 43
Joined: Fri Aug 30, 2013 11:19 pm

Re: GOOD Firewall

Post by dondavis007 »

I like to have control. When I connect a port on any service I want to, at least, be able to decide what device that can do what.
Everything, including, a normal windows is firewalled so off course I want to have a way of doing it on my backup. It's good to have a good firewall on hardware, but most are less than loosy. I you use it or not is up to the owner, but it should be possible. I see this question as a no question, in my case. I want it because I use it.
buhuhu
Posts: 120
Joined: Mon Oct 07, 2013 3:33 am

Re: GOOD Firewall

Post by buhuhu »

No response from ASUSTOR team :(