Before we go any further there are a couple of things to point out. This
FAQ is to provide an introduction to some of the more technical aspects
of firewalls. It is not necessary to understand this stuff to use a product
such as Zonealarm.
The people who might like to wander through here are
those who:
- want to use a product such as Tiny Personal Firewall to learn more
about firewalls
- want to understand what all those numbers are which appear in the firewall
log
- wish to do some sleuthing as to who is probing their computer
We have divided this FAQ in to four parts to make them more manageable and the contents is divided up as follows:
Part 1
A safe port in a packet storm
Protocols, tcp/ip, packets, ip addresses, ports, sockets, netstat and other tools
Part
2
So what is my firewall doing?
packet filtering, monitoring processes (in case of personal FWs)
Part
3
and how do I know?
logs, testing, recognising suspicious activity, packet sniffing
Part
4
Playing Sherlock Holmes
Using logs, whois, DNS, tools Sam Spade, websites, VisualRoute, synchronising
time, sending a complaint You will probably find it useful to work your
way through the parts in order.
