• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Home Network Switch Type

MichiganPC

n00b
Joined
Aug 19, 2014
Messages
47
At present my home network is on a 10/100 ProSafe VPN Firewall switch that sits behind a cable modem. A while back I added a 5 port gigabit switch for the media PCs.

I want to add more ports and clean up the distribution panel by consolidating to a single 10/100/1000 switch. I don't need the VPN features of my current switch.

Do I need a firewall switch? Or will the cable modems built in firewall be enough protection for a home network?
 
Last edited:
Its all personal preference, I use no fiewall, just a router and I use a 3com 4500g switch 24 port 10/100/1000 managed switch. they are less than 100 on ebay.
 
Cable modems are usually fine, if you're paranoid you can (usually) put it in bridge mode and add your own router/firewall/gateway of preference. However don't use bridge mode if you just are going to hook up a switch to it. In terms of switches the Zyxel GS1910/GS1920-series are considered good value switches that are managable and fanless. The 3Com switch mentioned above isn't unless Google is wrong.
 
the 4500g is managed, but yes it has fans, they arent very loud once it boots up. I keep mine racked in my living room
 
I'll second the reliability of the 3com 4500 series. I've got 2 4500G switches in my lab that were setup when they came out which I think was around 2007 or 2008. They have been in constant and somewhat heavy use since and were only touched when I moved the lab to a new building 3 years ago. They have never even hiccupped once in this time.
 
I would however be a bit reculant buying hardware that's 6+ years old...
 
I should have phrased the question better.

The firewall on my cable modem is very simple (3 settings) compared to the level of control my VPN/firewall switch has.

What I really want to know is the firewall on the service provider's modem adequate for a home network or should I get a managed switch&firewall?
 
Most everyone here, myself included, will tell you that you should put the cable modem into bridge mode and use your own router/firewall. Like so:

ISP ---- CM ----Router/FW-----users

I would add that wireless users should hang a separate routed+firewalled interface from the internal users and in general treated as untrusted. I would expect others here would deem that to complicated for most home users.
 
My current router/firewall/switch is 10/100. If I put all LAN devices on a gigabit switch is the 10/100 firewall adequate for internet traffic.

The two options I'm looking at cost about the same.

1) old 10/100 8 Port Firewall >> new 16 port gigabit switch
2) new gigabit 8 Port firewall to new 8 port gigabit switch

Is there anything to gain with a gigabit firewall for internet?
 
From a quick Google search that FW is rated at 60Mbps, meaning it is on the low end of performance but assuming your ISP connection is somewhat less than that no there will be little to no gain in replacing it. You would however gain something on your internal transfers assuming your internal devices are gigE capable in the following arrangement:.

ISP --- CM --- Router/FW --- Switch --- Users


Your local traffic would stay on the gigE switch and only the internet traffic would be transverse the router. You've made no mention of wireless needs so ...


EDIT:

Is your current FW a Netgear FVS318? If so I overstated the throughput earlier. That device is limited to 12.5Mbps firewall throughput and only 1.2Mbps vpn. What speed are you paying for from your ISP?
 
Last edited:
You would however gain something on your internal transfers assuming your internal devices are gigE capable in the following arrangement:.

EDIT:

Is your current FW a Netgear FVS318? If so I overstated the throughput earlier. That device is limited to 12.5Mbps firewall throughput and only 1.2Mbps vpn. What speed are you paying for from your ISP?
Yes the FVS318. I have 100Mps service that tests at 90/20 dwn/up from behind my FVS318 firewall. Are these tests just testing to the router. I tried 4 different test with the same result.

I have no specific need for VPN, it just cane with the switch. Most devices on the LAN are gigabit including a wireless access point.
 
Yes the FVS318. I have 100Mps service that tests at 90/20 dwn/up from behind my FVS318 firewall. Are these tests just testing to the router. I tried 4 different test with the same result.

I have no specific need for VPN, it just cane with the switch. Most devices on the LAN are gigabit including a wireless access point.

Don't know what to tell you. According the specs that devices is limited to 12.5Mbps and most complain about it being less than 10Mbps. Are you sure that your not confusing Kbps with Mbps? I''m seeing reviews of the device from 2002 so even without seeing anything it is unlikely a consumer or prosumer device from timeframe would turn in numbers like you're reporting. Out of curiosity what port of the netgear is attached to the cable modem?
 
Out of curiosity what port of the netgear is attached to the cable modem?
Port 1, so I guess I'm bypassing the firewall?

I remember now, quite a while ago I tried put the modem in bridge mode, had issues. I guess I forgot to go back and fix it :(
 
Port 1, so I guess I'm bypassing the firewall?

I remember now, quite a while ago I tried put the modem in bridge mode, had issues. I guess I forgot to go back and fix it :(

Then you're most likely running it in double nat mode already. (And not bypassing the built in firewall of the modem) If your modem has multiple ports then it's an all in one gateway. If you aren't opening ports to allow traffic in, then chances are that device already provides what you'd need. If you want additional security beyond what you have now then you'd want to shop for a device.

Simply plug a new gig switch into any of the ports on the modem, and plug devices into that. You should be able to get well over 100mbps as I'm assuming you Comcast with an extreme 105 package (I'm not aware of anyone else with 20mb uploads) so you should be seeing closer to 120mbps once you take away the old device.

You can check if you're in double nat by looking at the wan IP on your netgear. If it's a 10.x or a 192.x, then it's already behind the NAT of the modem.
 
Port 1, so I guess I'm bypassing the firewall?

I remember now, quite a while ago I tried put the modem in bridge mode, had issues. I guess I forgot to go back and fix it :(


Correct, you are not using the FW on the netgear. I'm guessing that you CM is not in bridge mode and is functioning as your router. Also ignore the double NAT business mentioned in the post above. You are not double natting if you are cabled as you've described.

My suggestion is:

1. Toss the fvs318
2. get a new router/fw
3. Get a switch if you need more ports
4. Once you get the new router/fw put your CM in bridge mode and attach your FW directly to it.
5. If you end up buying a separate switch I would suggest attaching only port of router/fw to the switch and attach all internal devices directly to the switch.
 
My suggestion is:

1. Toss the fvs318
2. get a new router/fw
3. Get a switch if you need more ports
4. Once you get the new router/fw put your CM in bridge mode and attach your FW directly to it.
5. If you end up buying a separate switch I would suggest attaching only port of router/fw to the switch and attach all internal devices directly to the switch.
One question, If I got an 8 Port FW and 8 port switch why not put the primary PCs on the FW and the network printer and other low bandwidth devices on the switch? Won't the switch channel all traffic through a single FW port?
 
One question, If I got an 8 Port FW and 8 port switch why not put the primary PCs on the FW and the network printer and other low bandwidth devices on the switch? Won't the switch channel all traffic through a single FW port?

You can certainly do that and it will work, but if you can keep everything on single switch you should. The KISS principle applies here:

As phrased by Cpt Montgomery Scott "The more they overthink the plumbing, the easier it is to stop up the drain."
 
Back
Top