Can i just turn the firewall off on my router?

milldakill

Member
Jul 24, 2003
42
0
0
I have a cheapy compusa brand router and I want to just turn the firewall off. First off is the firewall really that usefull for a home user with a cable modem. second, is it possible to turn it off and how?
 

JackMDS

Elite Member
Super Moderator
Oct 25, 1999
29,527
415
126
All Entry Level Cable/DSL Routers by default are NAT-Firewall. Some have additional protection like Statefull Package Inspection (SPI).

When you use few computers to share one Internet connection, the information that comes from the Internet needs to know to which computer it belongs. The main function of Cable/DSL Router is to Route the Internet signal to the requesting computer. This function is called Network Address Translation (NAT).

As result information that comes from the Internet and was not requested by one of you LAN's computers (e.g. hacking attempts) does not know where to go, and it is blocked, hence NAT Firewall. Actually the NAT-Firewall does not do any thing active concerning the content and the nature of the information, it does not know what to do with the none requested Info. that is coming in and blocks it.

I.e. No NAT-FireWall, NO Routing.
 

milldakill

Member
Jul 24, 2003
42
0
0
i think i know what your talking about (kind of) but the firewall does seem to screwup some requested information in example i cant create games on Battle.net for warcraft 3 when i gor through the router. And if you know anything about DMZ (demilitarized zone) please share what you know, cause when i put my comps IP in for that i can host on Battle.net. It was explained to me as being outside of the firewall funtions of the router, but you can only put one IP in, (probably so the NAT Firewall knows where to send unrequested info?) but if there is any reason not to use the DMZ please tell me
 

Zucarita9000

Golden Member
Aug 24, 2001
1,590
0
0
Basically, all machines (IPs) inside the DMZ are unprotected by the NAT. If you want to run a web server, a game server or whatever, you should put it in the DMZ.
 

JackMDS

Elite Member
Super Moderator
Oct 25, 1999
29,527
415
126
Three Options.

1. Get rid of the Router.

2. The gaming computer can be put on the DMZ.

It means that the Router can put one of your network's computers in front of the Firewall.

The computer is chosen by its IP number. Consult your Router's manual to the specific settings and menu.

3. Port Opening.

You can open ports through the NAT-Firewall and info can come in through these ports regardless of the NAT.

A. All Routers let you define few individual ports

B. Port Range - Most Routers let you define a range of ports to be kept open (e.g. 5000-6000).

C. Port Triggering (available in some Routers) - Applications that connect to the Internet by using port X expecting an answer through port Y. Port Triggering makes sure that port Y is available to receive the answer.

The way to open a port depends on the Router. Each manufacture has his own "Shticks" to go about it. Each one has his way of organizing the Menus. You have to read the Manual in order to know how to do it. The term that it is referred to could be Port Mapping, Port Opening, etc. In a Virtual Server.

List of ports that are associated with various applications can be found here:

Special Applications - Port List.