Question
April 3, 2008 at 10:07 AM

Firewall on Two nVidia Integrated Network Adapters

Hallo everyone !

I have a Tyan S8295 K8WE motherboard with two integrated 1Gbit network adapters. In my
motherboard’s manual description of features it is stated:

Integrated Secure Network Processor:
Two IEE 802.3 Nvidia MAC 1000/100/10 Ethernet
( First from PRO 2200, Second from PRO 2050 ).

When installing drivers for the motherboard, the option is also to install Nvidia
Network Manager for Nvidia firewall. I decided to install it, but not enabling it, since I do not really know nothing about it, and just let the Windows XP 64bit firewall enabled.

Yesterday when I was reading the manual about this Nvidia firewall features ( just went through briefly ) I was somehow impressed on features this ( actually hardware integrated ) firewall offers.

The problem is I do not know much about firewalls and all the features this kind
of protection offers, but I thought to myself, since I have two of these Nvidia adapters integrated, why not give it a try.

My office network consists of thre computers: two running Windows XP 32bit and one running XP 64bit. I have a ADSL modem connected to 100Mbit router with some firewall features built in, for which I somehow allways thought, it protects the getaway and the network just by itself. But now I am realising this
ain’t the fact. If you do not set the rules, how could something like built in firewall
really protect something. I guess I am not wrong. Please correct me if I am.

I was thinkg about connecting internet connection to one router and adding one
more router for just internal network traffic. By installing some internet security
suite on all computers, I would than deffine Unsecure zone for internet traffic
adapters and Secure zone for the internal network traffic adapters. I am still in
doubts about that solution, since I do not know if it would really give my network
additional protection. Actually I was talking about Panda’s network security suite,
which has software firewall integrated, have wrote to them about the concerns for this kind of solution, and got no answer from them. Any thoughts, please comment.

From yesterday I am thinking how could I use these two Nvidia hardware firewalled
network adapters integrated on my motherboard. There is a possibility to bridge them – still do not know what that actually does. I can of course make ( provided by Windows software ) internet sharing connection. So I could potentially make a direct modem connection to one of these adapters. Then make a connection
from the second adapter, which would actually serve for sharing the internet connection, to my router, which could actually be unfirewalled, since I would astablish all the rules for the motherboard’s firewalled adapters. The router would than provide all the internet traffic and internal traffic between my computer and other two computers. Hm, does this make any sence to anyone ?

Or does anyone think a strong firewalled router would be the best solution. How about still separating the internet and internal network traffic?

Since I am really hot about the security topics,
I will get of course much deeper in the security
area by myself, but in this moment ( I work
in a law office as an office assistant and network administrator ) I do not have that much
time for studying the security topics as I would
love to. Besides in our office have decided to
start with a real server ( Windows Server 2008 )
at the end of the year, so I have to study that
area too – I have about 8 months to test this
server with a Microsoft’s testing version of this operating system. I also realise that
security matters after starting with a server will become a much heavier issue and a totaly
different approach will be needed compared to
with what I am dealing in this moment – a
small bussiness network ( actually more home like ) with no server at all.

I really appriciate all the comments, so thank you very much for all of them.

Greets. Miro.

This discussion is locked

All Comments