Re: publications concerning port forwarding



Ben Nell writes:

Could you please explain your reasoning behind the inherent flaws in
port forwarding?
[...]
security practices would warrant port forwarding only to DMZ subnets.

I think that's the problem here: port forwarding from internet directly to
internal core systems. I don't see many problems in port-forwarding towards
DMZ systems.

With a direct connection to the internet (regardless wether via routing, NAT
or port forwarding) the target system has to be able to withstand the usual
internet attacks - known exploits, DoS (at least to some extent e.g. through
intensive use), fuzzing. Applications (especially web-applications) have to
be resistant against XSS, XSRF, etc.

Usually internal systems are not as hardened or programmed with security in
mind as the ones which are intended from the beginning to be placed in the
internet.

And if these systems were taken over, they had direct access to your core
internal network. Systems set up for direct internet exposure in a DMZ
should be harder to crack - and then an attacker still is behind a
firewall...


I'm currently doing work for a large company as a consultant. Another
consultant is installing a MS Exchange server and is now requesting for me
to forward ports on the PIX from the Internet to internal servers.

Which ports/services? While SMTP and HTTPS (for OWA) could be okay-ish,
opening MS RPCs ("naked" MS-Exchange) to the internet quite probably is not
such a great idea.
;-)

Even if you were asked to forward SMTP (incoming) only: with Exchange you
sometimes need to shut down the MSX server for maintenance work. And during
this time mail will bounce as undeliverable as the MSX SMTP connector will
be unavailable, too. Plus the MSX SMTP connector is not as forgiving to SMTP
protocol misuse as e.g. a Postfix server. Thus placing a plain SMTP server
simply as cacheing proxy between MSX and the internet will catch both flies:
no direct connection between the internet and MSX, bette SMTP compatibility,
better spam control and filtering, a cache for MSX maintenance downtimes,
plus (optionally) a border virus scan (e.g. using the free ClamAV).


Bye

Volker

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.

http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------



Relevant Pages

  • Re: How do I change the port for remote desktop in win2003?
    ... >>It's not really a dual lan, it's a NIC on WAN and a NIC on ... >>local network. ... >>It's still a bad idea to put Windows 2003 server directly on the Internet. ... even NAT is better than a direct connection. ...
    (comp.security.firewalls)
  • Re: Why sending email programmatically must be so complicated?
    ... > All of them involve direct connection to Internet and extra other ... > Outlook Express or Outlook and the computer is already connected to ... > such components tend Windows to warn potential user about hazards such ...
    (microsoft.public.vb.general.discussion)
  • Re: Why sending email programmatically must be so complicated?
    ... All of them involve direct connection to Internet and extra other ... Outlook Express or Outlook and the computer is already connected to ... I do not want to use any extra components, ...
    (microsoft.public.vb.general.discussion)
  • Why sending email programmatically must be so complicated?
    ... All of them involve direct connection to Internet and extra other ... Outlook Express or Outlook and the computer is already connected to ... such components tend Windows to warn potential user about hazards such ...
    (microsoft.public.vb.general.discussion)
  • Re: Exchange Help Please!
    ... CANNOT RECEIVE EMAIL FROM THE INTERNET TO EXCHANGE SERVER ... >> Website allows me to change my own DNS records for the domain wolaz.com ... >> I've used the mail system for the website as the backup MX ... >> 1 - Direct Connection to Internet ...
    (microsoft.public.windows.server.sbs)