RE: [fw-wiz] OT: Av and Gartner...

From: Bob Wanamaker - Avant Systems, Inc. (rlw_at_avantsystems.com)
Date: 07/31/03

  • Next message: Jim McAtee: "Re: [fw-wiz] OT: Av and Gartner..."
    To: "'John Keeton'" <jkeeton@nettoxin.net>, <firewall-wizards@honor.icsalabs.com>
    Date: Wed, 30 Jul 2003 20:37:20 -0400
    
    

    My standard recommendation: don't worry about http/ftp scanning, but do
    have AV installed on the proxy server. AV should also be installed at SMTP
    gateway; an Exchange-aware version on Exchange server [and please note that
    SMTP gateway is on a separate box and on a DMZ segment from corporate
    Exchange server]; on all servers; on all desktops.

    Additionally, block the majority of attached files on your Exchange server.
    Use a scanner that actually works, and test the snot out of it - you'd be
    surprised that scanners let EXE's embedded in a Word document come through,
    but some do. Proxy server should be capable of blocking downloads as well -
    for example, the most recent WMP flaw requires that a MID file be used in
    the exploit; answer - block MIDs.

    Only permit required hosts to traverse the firewall. No desktop should have
    to do this.

    -----Original Message-----
    From: firewall-wizards-admin@honor.icsalabs.com
    [mailto:firewall-wizards-admin@honor.icsalabs.com]On Behalf Of John
    Keeton
    Sent: Wednesday, July 30, 2003 7:10 PM
    To: firewall-wizards@honor.icsalabs.com
    Subject: [fw-wiz] OT: Av and Gartner...

    Slightly OT here.

    In corporate land, where does everyone have AV installed? Currently, we
    have desktop, NT servers, and email gateway. I am thinking that we need
    http/ftp scanning via ICAP from our proxy, but Gartner[1] says http/ftp
    scanning is uneeded. I don't know if I agree.. -OR- Are people installing
    malicious code detection software, like www.finjan.com??

    Also, anyone have any experiance with Garner regarding security items? This
    AV answer, joined with their latest magic quad. for firewalls and ids is
    just plain scary. I don't know if I even want to put an ounce of faith in
    them anymore.

    Thanks,
    -jkeeton

    [1] At my employ Gartner is god.
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Jim McAtee: "Re: [fw-wiz] OT: Av and Gartner..."

    Relevant Pages

    • RE: smtpsvc error id 115
      ... installing any version of Outlook on the server which has exchange ... Microsoft does not recommend installing Exchange Server and Outlook on the ...
      (microsoft.public.windows.server.sbs)
    • Re: Exchange 2007 - conversation with [exchange2007] timed out while receiving the initial serve
      ... I was checking some email queues on the Exchange 2007 server earlier ... What is your opinion of installing the SP2? ... We already have the Server ... Microsoft Exchange Transport service. ...
      (microsoft.public.exchange.admin)
    • Re: Mail delivery wierdness
      ... That's usually the behaviour indicating that there is a server at ... MS Exchange is pretty far beyond the ... FreeBSD gateway?). ... SMTP is a connection-oriented service. ...
      (freebsd-questions)
    • Re: how to safely remove exchange from sbs 2003
      ... web server only. ... If you think installing patches and security updates is expensive, ... Exchange is the single most integrated part of SBS. ...
      (microsoft.public.windows.server.sbs)
    • Re: event id 467
      ... Server was backed up last night, so I guess I will run the ... Have you run Chkdsk /f or chkdsk /r on your drive. ... a warning about installing Win Server 2003 SP2 may fail (i ... Exchange server folders when installed on Microsoft Exchange server" ...
      (microsoft.public.windows.server.sbs)