G'day Silvertones,
umm, which firewall?

Ports 137, 138 and 139 are the NETBios ports on TCP/IP - these need to be open for sharing to work. For the most part, it's probably redundant to worry about a personal firewall on a local net that is behind a NAT gateway. Of course, if you DO get compromised it can spread fairly quickly then...

However, by opening those ports for local sharing, it will spread anyhow... You either share or you don't. If you do, the firewall becomes redundant as you have to defeat it anyhow.

Personal firewalls do nothing to protect you if you are behind a NAT gateway as the gateway (router) is already preventing direct access to your PC's. The only exception to this would be if you have setup a DMZ that points to one of your PC's. In this case, it is directly exposed to the internet via the DMZ redirection.

If you don't have a DMZ redirection just leave the firewalls off... Unless you want to get really creative in the firewall filter configuration, but you'd need to buy something fairly sophisticated to make it worth while.

Last edited by Lawrie; 02/06/09 04:10 PM.

--=-- My credo: If it's worth doing, it's worth overdoing - just ask my missus, she'll tell ya laugh --=--
You're only paranoid if you're wrong!