Re: [fw-wiz] question on securing out-of-band management



MJR wrote:
For the sake of tradition, I would recommend duct-taping the
dongles in place. ;)

Where I learned the trade, hot melt glue is the tradition (no joke).


On 2/3/06, golovast <golovast@xxxxxxxxx> wrote:
Thank's for all the replies. See inline.
Unfortunately it won't be on a completely separate switch.
For a variety of reasons, our management network is going to be used to
manage both the perimeter and the internal servers, so on the back end it
will be connected to the internal core switch. We'll probably run IOS with
firewall services there, so the users should be restricted from accessing
the network.

IMHO, this design is basically one bad IOS command away from compromise,
and is risky on multiple fronts:
1) Relying on router/switch security to isolate the management VLAN.
2) Connecting the OOB management VLAN to the internal core switch.
3) Using the same management IP network for perimeter and internal servers..

Do you trust Cisco VLANs and "IOS with firewall services" to this degree?


A real-world example, the perils of mixing OOB data into the production network:

At my employer, the server admin team petitioned the network team to deploy a
new "tape backup" subnet which was supposed to be it's own isolated unrouted
subnet, connecting the tape backup server to Windows and Unix servers.
All was well, backups happened quickly.

Then more servers were added, and the isolated segment became an
unrouted VLAN across multiple switch fabrics, and things were still okay.

Then the server admins decided they needed to manage the backup server
(which "couldn't" be multihomed) from their desk, so the "unrouted" subnet
became a routed segment, and things started to get messy, backups took
longer and longer to complete.

Fast forward a couple of years. One day I'm running windump on a user
workstation (not a server, not backed up to tape), and notice WINS packets
from the desktop to an IP address on the "isolated" backup segment.
I think to myself "WTF?!?".

As it turns out, the primary domain controller automagically decided to
return, as it's primary IP, the address for the PDC's interface on the
backup segment. And to this day we have not successfully be able to
re-isolate the "isolated" backup segment.

Kevin
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxx
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards



Relevant Pages

  • RE: SBS Back up Failure
    ... attached the log and report from yesterday's backup also. ... One or more components of Small Business Server Backup failed. ... recommended that you review errors in the Event log related to the service. ... Notifications task in the Server Management Monitoring and Reporting taskpad. ...
    (microsoft.public.windows.server.sbs)
  • Re: MSKB 891957, VSS Update for Windows Server 2003
    ... Well, it turns out the RDP connection dropping issue won't go away, ... level to the server in the office may have an affect on the issue. ... I just remembered I also re-installed RDP Client V6 last night as ... I left the server with user Backup logged in when I left the ...
    (microsoft.public.windows.server.general)
  • Re: MSKB 891957, VSS Update for Windows Server 2003
    ... I left the connection sit idle and checked back in an hour. ... server and browsed around for a few minutes. ... it would seem that there is still some issue with the V6 RDP ... I left the server with user Backup logged in when I left the ...
    (microsoft.public.windows.server.general)
  • RE: Server Management Backup Page Not Found
    ... reinstall backup and monitoring components. ... Perform a full backup of the SBS server. ...
    (microsoft.public.windows.server.sbs)
  • RE: HTTP 404 errors
    ... NIC (network Interface Card) in our configuration. ... "Company Web Page" or to list the backup results in the "Server ... Backup program is functioninng properly, but the part that lists the results ... Server Management -Backup - Monitoring and Reporting ...
    (microsoft.public.windows.server.sbs)