Firewall placement?

From: Darren Breidigan 
Is there a preference or best practice for firewall placement for a SOHO?


Does it matter whether there is a  router/firewall or a embedded 
[Rasp/Pi] setup?

Just an experiment for a local shop that still does almost everything by 


=============================================================== From: Aaron welch ------------------------------------------------------ Most scenarios have the router and firewall as the same device. -AW

=============================================================== From: Christopher Rimondi ------------------------------------------------------ If you will rely on this firewall to view logs then place it somewhere it can see the internal IP addresses, i.e. that it just won't see a NAT'd IP.

Come again, slowly this time? Where would you put your firewall where it would not see internal IP addresses in a SOHO environment? Since SOHO firewall or router really both mean NAT device? It really depends on your topology and what you want to accomplish. If you have Cable Internet, then you will have a router (SMC gateway) and then a firewall. If you are on EPB, you can WAN straight into your firewall. I prefer a proper border router in front of my firewall, but that requires someone asking EPB for a routed circuit for their statics. No such option with Comcast, you just get to deal with their bridge, you don't have a single choke point if you have more than 1 static. Regards, dtb

=============================================================== From: Ed King ------------------------------------------------------ I prefer my firewall between the passengers and the engine ;)=0A=0A=0A=0A= =0A

=============================================================== From: Chad Smith ------------------------------------------------------ Leiningen puts his firewall between himself and the ants. *- Chad W. Smith*