Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Do you need to have Windows Firewall on if you have a hardware firewall

Posted on 2016-11-13
9
Medium Priority
?
215 Views
Last Modified: 2016-11-30
If you have a hardware firewall installed like a Sophos UTM is that reason to turn off Windows firewall?  I'm curious

Thanks
0
Comment
Question by:Peterson50
9 Comments
 
LVL 99

Expert Comment

by:John Hurst
ID: 41885707
A good third party software firewall will take over from Windows Firewall. I use Symantec Endpoint and its firewall takes over from Windows Firewall. So Windows Firewall may already be disabled.

If you have no third party software firewall, there is no harm in leaving Windows Firewall intact. Just leave it.
0
 

Author Comment

by:Peterson50
ID: 41885711
My IT partner feels its okay to leave the workstation firewall disabled, its not necessary, is that accurate?
0
 
LVL 99

Accepted Solution

by:
John Hurst earned 2000 total points
ID: 41885714
Yes it is fine, so long as you are always behind the Sophos Hardware Firewall. This is normally true for Desktop computers.

For any laptop that travels away from the hardware firewall, then some sort of software firewall should be on the computer.

I think that makes sense.
0
New Tabletop Appliances Blow Competitors Away!

WatchGuard’s new T15, T35 and T55 tabletop UTMs provide the highest-performing security inspection in their class, allowing users at small offices, home offices and distributed enterprises to experience blazing-fast Internet speeds without sacrificing enterprise-grade security.

 
LVL 19

Expert Comment

by:Mal Osborne
ID: 41885732
I would not disable the Windows firewall.  This give you protection form other machines on the network that may be infected with malware, or foreign machines connected to the LAN.
0
 
LVL 32

Expert Comment

by:Mark
ID: 41885751
Using both will be complementary to each. The hardware firewall will protect most incoming network traffic and the software firewall will be in a better  position to analyze the PC 's behaviour as it can be aware of both incoming and outgoing traffic from the PC itself i set up that way. The problem is that windows firewall doesn't do a very good job of checking outgoing traffic unless it is set up properly, not very user friendly. But using both should not be an issue. There are 3rd party software firewalls that will work better than windows firewall.
0
 
LVL 99

Expert Comment

by:John Hurst
ID: 41885755
As I noted earlier, I use the Symantec Software Firewall and it does an excellent job on my ThinkPad.
0
 
LVL 3

Expert Comment

by:Yogesh Patel
ID: 41885857
Its safe to keep both firewall on as both firewall doing different job.

Hardware firewall provide you Gateway Level security and Windows firewall give you OS level security as it will protect you network from spreading .

Hardware level firewall validate Incoming and outgoing access and block it at Gateway Level so its dont go to you PC.

But in some cases unauthorized access through any Software download like Malware or any  Software Installation from media , your windows firewall prevent it from spreading to Network.


 Its like double layer security if you keep both on
1
 
LVL 57

Expert Comment

by:Pete Long
ID: 41886073
My $0.02

The "Turn the Windows Firewall off because we have a hardware firewall" Is ingrained in a lot of techs, because when XP SP2 came out and enabled the firewall, carnage ensued, In Microsoft's defence thats was primarily because of badly coded applications. but the practice of disabling the windows firewall has stuck ever since.

As already mentioned if you have a third party firewall software (on the client's) then by all means, disable the Windows firewall.

However: Your most vulnerable attack vector, is from within. When "Julie" in accounts clicks an email attachment and sets up some malware that starts scanning for open ports to attack, what good is you state-full firewall then! In fact I've seen the same people who disable the Windows firewall, have "permit IP any any" outbound on their corporate firewall, so they can proliferate and infect everyone else (cheers for that!)

So leave them on! If they stop something working, get Wireshark fired up and fix that problem. Disabling a firewall without having other measures to protect your endpoints, is like having a UTM firewall thats scanning for AV/AMP so you don't bother putting AV/AMP software on you clients! You wouldn't do that, so why disable the firewall?


Pete
2

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Arrow Electronics was searching for a KVM  (Keyboard/Video/Mouse) switch that could display on one single monitor the current status of all units being tested on the rack.
A 2007 NCSA Cyber Security survey revealed that a mere 4% of the population has a full understanding of firewalls. As business owner, you should be part of that 4% that has a full understanding.
How to fix incompatible JVM issue while installing Eclipse While installing Eclipse in windows, got one error like above and unable to proceed with the installation. This video describes how to successfully install Eclipse. How to solve incompa…
In response to a need for security and privacy, and to continue fostering an environment members can turn to for support, solutions, and education, Experts Exchange has created anonymous question capabilities. This new feature is available to our Pr…
Suggested Courses

916 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question