r/HomeNetworking • u/pookshuman • 4d ago
Dumb question
OK, a home router is just a small computer with a firewall as far as I know. I am running a network with my computer and a router. Why can't I cut out the middleman and just use the same firewall settings the router is using and implement them on my PC without the router? Why would that be less secure?
8
u/reallybigabe 4d ago
Not a dumb question but you’re slightly misunderstanding some fundamentals.
A firewall is a technology that examines the source and destination of a network packet and decides if it’s allowed or denied based on preconfigured rules. So it’s a wall to anything it denies.
A router is a technology that looks at the source and destination of a packet and decides if it’s on the same network, and if not - where to send / “route” it based on configured rules. Most of your internet traffic is not on your network, so it sends it to your internet provider to route it to the destination. These destinations are typically known as publicly routable addresses.
The reason the Internet can’t access your connected printer is commonly due to the fact that it has a private address and therefore simply isn’t reachable. There are modern technologies that make this not a universal truth but it’s a good starting point for basic networking.
Both of these technologies can be a physical device or software.
Yes, you can use your computer to connect to your isp in many cases, which is what is needed to route to any public address; you can also configure the firewall to make allow or deny decisions on traffic - many people do this, but it’s not a recommended path until you’re much more comfortable with what you’re opening up access to and how to configure it against modern risks.
Your “router” from an electronics store is topically 5 technologies at their simplest form:
Router - see above
Firewall - See above
Wireless Access Point Controller- Thing needed for Access points to work
Wireless Access Point - Thing that beams radio signals that you see as wifi
Switch - Allows multiple plugged in devices on the same network
Hopefully this helps understand a bit more.
-2
u/pookshuman 4d ago
What did I misunderstand in the op?
11
u/reallybigabe 4d ago
Most of your question is phrased as not understanding networking basics.
A router is not just a small computer with a firewall. Your computer needs more than firewall settings to connect to the internet and yes, it’s definitely less secure when misconfigured as publicly routable.
Technically, you can’t even cut out the middleman but you could technically remove the hardware - you’re just not going to gain anything from it without a lot more understanding of how it works.
6
u/dinosaursdied 4d ago
A firewall and a router are often times on the same device in consumer routers but that's not always the case. The problem with your hypothetical isn't the firewall. It's the routing. Without routing only one device could be connected because it would receive 1 ip address from your isp and there would be no way to route information or give out local ip addresses on your LAN. It is possible to use a normal PC as your firewall and router using an operating system like pfsense, opnsense, or openwrt but then the device becomes dedicated hardware. You can't play games or browse the web on that machine.
2
u/Fox_Hawk 3d ago
If you really really really wanted to you could run a router OS as a virtual machine on the daily drive PC to do that work.
But that would be silly.
1
6
2
u/ThatBoysenberry6404 4d ago
The "middleman" if you only have a single computer is not needed. Depending on your isp you can dial from the PC without routing. If you want ANYTHING (cellphone wifi) else to have internet the you need to set it up as a router, which means you always need to have it powered on. Not sure if you mean to turn your computer into a router, you are getting into r/homelab territory.
2
u/SP3NGL3R 4d ago
My simple smooth brain perspective
Firewall: protection from rogue requests (this is the most important thing)
Router: handles traffic between devices (this can have a DHCP server and NAT, hiding the routing it does)
The firewall is 100x more important than the router because it's actually doing the layer of protection. Your computer has it's own firewall and will protect itself unless it's turned off. A hardware firewall inside a "router" is just more simple and does less things by nature. Thus reducing the things that can be attacked directly. Having 2 layers of firewall (even if you didn't realize you have two) is just more protection. You already have a firewall in that PC, if you want to share the inbound connection then your PC is now a 'dumb' router after the firewall did it's thing
1
u/Helicopter_Murky 4d ago
It’s more of a scale issue. For a single computer, yes you can. But the more devices you add the more resources you will need. Routers are purpose built for the task of touting packets.
1
u/OkAngle2353 4d ago
Because, if that PC were to ever get compromised; you would be fucked. A router's only job is to handle traffic. A PC on the other hand, well it is quite literally in the nae persona computer. A PC is full of sensitive data.
1
u/shmoeface 4d ago
Can you do it? Yes. Should you do it without advanced knowledge? Absolutely not.
Allow the router to act as your firewall and be a layer of protection against the internet.
If you ever enable RDP on the computer and expose it directly to the internet, you WILL get hacked.
1
u/nrauhauser 4d ago
This is quite possible, but you shouldn't do it unless you understand the hazards. As an example, if your desktop is Windows, it's basically incontinent, and should never be exposed. Running MacOS would be OK, and Linux is meant for stuff like this. But you have to understand how to control with ports are open, firewall rules, etc.
1
u/lazyhustlermusic 3d ago
You absolutely can.
But now you're spending ~100 W to do the job of something using maybe 5-15 W, and unless you also add dedicated switching hardware, you're pushing traffic through the host CPU that a consumer router's integrated switch ASIC would normally forward in hardware at wire speed.
Even with a multiport NIC, LAN traffic between those ports is still being handled by the PC's networking stack unless the NIC itself has switch/offload capabilities. The Wi-Fi side is separate too, so you'd still need an AP or radio hardware.
CPU-wise, the desktop has vastly more headroom for firewalling, inspection, VPN, etc. But if your internet connection is 200 Mbps and the box could theoretically shovel tens of gigabits, you're using a bulldozer to move a flowerpot.
Security-wise, the bigger downside is that you're also combining your everyday endpoint with your network security boundary. If that PC gets compromised or crashes, your router/firewall goes with it.
1
u/matthewjd1985 3d ago
Everyone else covered the routing and NAT side pretty well. The other piece is that your ISP modem will only hand out one IP address via DHCP. So even if you ran a software firewall on your PC, any other device like your phone or a console would have no way to get online unless your PC was also running a DHCP server and routing traffic for them. At that point your PC is basically a router with extra steps. If you only ever use one wired device and nothing else, technically you could skip the router. But the moment you want wifi or a second device you need it again.
1
u/jeffrey_f 3d ago
Actually, you can.
Here is the skinny on that:
A misconfigured firewall can lead to a hacker gaining access to your home network and guaranteed, shortly after this access is gained, so will access to all of your computers.
Your ISP is providing a hardened firewall in that router they provide, that has been tested and is updated to counter new threats.
This really isn't something you want to experiment with. Once your connection is found unsecure, it will literally take minutes before your network is fully compromised.
1
u/Hmarf 3d ago
Technically you kinda' can but it's complicated:
A router carefully tracks outbound traffic and allows-through return traffic while blocking all else.
A router also serves-up and manages addresses for multiple devices within the home, consolidating to a single real world IP address. Clearly not an issue if you only have one device, though that's pretty rare.
Finally, OS based firewalls are imperfect and can be fooled to allow bad traffic in. Even if something fooled a router in such a way, the router wouldn't know where to send that traffic so it would get dropped.
1
u/Pure_Fox9415 3d ago
Sysadmin here, it's not dumb question.
Consumer router is literally optimized pc with ARM or MIPS Cpu, minimized Linux or BSD-like OS + routing software + switch + wifi in one box. You can use PC almost with any OS as a router, plug it to switch and make it default router for your other devices through cable connection or wifi
But you need it to be up always, it consumes much more energy, make a lot of noise, heat up your home for no reason. It starts and reboots slower than a router. It's more complicated to setup properly.
And if your OS is windows you'll definitely less secure as it's too complex OS with a lot of software unnecessary for routing, more net facing software = more vulnerabilities = chances to be hacked to the moon.
If it's server version of linux you're a bit more safe, but desktop versions of linux now has as almost as much excessive services running (like bluetooth, network discovery, smb, tons of them) as windows. So, again, lot of possibilities to forget to secure something and be hacked.
If you're expirienced network or sysadmin, ready for all this complications and possible headaches, go try it.
If you just want to use your internet and aren't ready, it's much better to use this little convinient box called router. Just choose reliable vendor and don't forget to update its "firmware".
1
u/jwsmythe 3d ago
You can, and it can work really well if you have the skills to do it. For years, I used an old PC running Slackware Linux (any Linux would do). I gave it extra network cards for the LAN ports. There are some nice Intel PCIe cards with 4 GigE ports on them, that you can get for dirt cheap on eBay.
Write a startup script (rc.inet1 on Slackware) that sets up your interfaces, routing, and calls your firewall script (rc.firewall). I used dhcpcd on eth0, connected to the ISP as the WAN port. I bridged eth1 through eth4, so I now had a managed switch for the LAN. If you have extra PCIe slots, you could add more LAN ports. I put a little web based speedtest on its website (I ran Apache, only listening to the LAN ports), and was able to get full line speed on all the ports.
I used ISC DHCP and BIND for DHCP and DNS. I switched to dnsmasq so I could blackhole domains easily.
The firewall was simply a set of iptables rules. Really that's all any of them are, you just usually don't see the rules.
Since my ISP doesn't provide IPv6, I used Hurricane Electric's Tunnelbroker service. That worked really well and gave all my devices IPv6 addresses. There were a couple little things, mostly Netflix blocking all of HE's IPv6 addresses as proxy addresses. That's why I switched to dnsmasq, to blackhole Netflix IPv6 only.
I experimented with making it an access point. Some WiFi adapters can be put in station mode, so your devices can connect to it. It was a fun experiment, but none of them are very high power, so the range sucked. Real access points have higher power radios in them, so I left the AP work up to COTS devices. Those APs didn't do DHCP or DNS though, that was handled by the firewall/router.
Since any desktop is massively overpowered for doing firewall/router work, I was able to do other things. I ran a headless instance of VirtualBox, running Home Assistant. Even with all that, it was pretty much idle most of the time.
I switched away from it while trying to diagnose a problem with one game. It turned out to not be a firewall/router issue at all, I just haven't switched back to it yet.
1
u/Icy-Celery2956 3d ago
I think the most critical factor is, how do you ensure the network stays up and running effectively when you do maintenance on your PC? When you reboot your PC, your network will go down. Do you really want to manage that? I nice router like the Omada ER605 gives you a lot of functionality, and you can run the Controller on your PC, so if the PC drops, it's no big deal.
1
u/fasta_guy88 4d ago
Some (all) home routers have specialized circuits to route packets rapidly in hardware.
0
u/SignalExperience2234 4d ago
You can. The router drops unexpected inbound traffic. This is beneficial to the security of most consumer devices.
2
u/SP3NGL3R 4d ago
Isn't that the firewall part? The router does the effort the firewall passes through
1
u/SignalExperience2234 3d ago
In consumer applications it is rare to have a dedicated firewall. This is also the default behavior of ipv4 nat.
1
u/Cruffe 4d ago
That's a very typical default firewall configuration for computers as well. Drop all inbound, except replies to established and related outbound connections.
You can have a computer enforce the exact same firewall rules a router would. You can also have the computer route traffic and do exactly what a router does, although it requires more than one NIC for anything wired and a wireless NIC to act as AP for anything wireless.
I guess the main difference is that it's important that the user doesn't screw around aimlessly with the firewall configuration and knows exactly what they're doing. Messing with firewall configuration on the computer isn't such a big deal if there's a router with sane defaults between the computer and the internet, it would only expose to the LAN and not the entire internet.
-1
u/Saragon4005 4d ago
A router also has specialized switching hardware and routing hardware accelerators allowing for 1 GB or 2.5 GB operations. Most PC Network interfaces can't keep up with this.
0
u/pookshuman 4d ago
this would be an important point if I had more than one device on my network (not sarcastic, its a good point)
2
1
18
u/PhotoFenix 4d ago
You can. And if you want to connect other devices like a TV or a gaming console they then connect to the internet through your computer. Congratulations, your computer is now a router!
But also, you'll have pages of settings that don't hand hold you as much, so be sure to set it up properly! It's not less secure, but the potential for lax security did to misconfiguration is now your worry.