[fw-wiz] Firewall Placement Question



I would like to hear some thoughts on the placement of a firewall. My
intent isn't to start a flame but to debate the usefulness of two
technologies inside the network firewall vs. IPS's.

The network which I manage is a university network that hasn't been looked
after very well with regards to security and access control. Right now
there is a head end firewall that's 'inverted' as we say - that is we
allow everything and just block a few things.

Between buildings we block a few ports on the l3 switches to 'contain
outbreaks'.

There are three major problems which we are trying to address separetely.

1. The Residence Halls are on the inside of the network. They are coming
off this summer.

2. Wireless users are on the inside of the network. We are building a
'guest wireless' system that will be live this summer as well.

3. There are open network jacks all around campus and no kind of NAC in
place. This isn't being addressed yet.

Also being a university we have a hard time trusting our users and
enforcing anti-virus installations and patching.

Recently there has been a push to install a transparent firewall in front
of the server farm. This is being done using a context on our firewall
services module that protects (be it poorly) the border at the internet.
However both the server network and internet border are being scanned by
an IPS.

The question is: given that we are working to take historically abusive
users off the network, is it really worth the time to install a firewall
in front of the servers or just use the IPS?

I wonder about the labor required to pull this off for almost 200 servers
(and Microsoft applications are a bitch). I fear it will be hell to
manage all the excpetions, ie. one user in a different building needs
access to a few administrative ports. Not to mention that after it's done
we'll spend days trying to work out the bugs of things that 'should just
work' and effects of application upgrades that change ports.

Lastly, is anyone doing any kind of filtering inside the network or is
only done at the border?

Thoughts?

Regards,
Jason Mishka
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards



Relevant Pages

  • << SBS News of the week - Sept 26 >>
    ... And he points to the info you need to put the file on the server in the ... at the network perimeter. ... The Symantec Firewall/VPN and the Gateway Security ... by the firewall at risk. ...
    (microsoft.public.backoffice.smallbiz2000)
  • << SBS News of the week - Sept 26 >>
    ... And he points to the info you need to put the file on the server in the ... at the network perimeter. ... The Symantec Firewall/VPN and the Gateway Security ... by the firewall at risk. ...
    (microsoft.public.windows.server.sbs)
  • << SBS News of the week - Sept 26 >>
    ... And he points to the info you need to put the file on the server in the ... at the network perimeter. ... The Symantec Firewall/VPN and the Gateway Security ... by the firewall at risk. ...
    (microsoft.public.backoffice.smallbiz)
  • Re: need help re. office network install
    ... > and their network is a mess, the result of years of neglect. ... they have a gateway server w/ no special ... > firewall rules on it, they have a large DMZ that serves no purpose ... install anymore software on the firewall machine than is absolutely ...
    (comp.os.linux.networking)
  • Re: oops again
    ... open on the Firewall, and the default should be none. ... Since you intend to install IIS purely as a test server for your ASPX pages ... Make sure that IIS is only listening on the local network (192.168.x.y ...
    (microsoft.public.inetserver.iis)