Re: Backup for win2k boxes in the DMZ

From: Dennis Depp (deppdm@ornl.gov)
Date: 02/15/02


Date: Fri, 15 Feb 2002 13:19:01 -0500
From: Dennis Depp <deppdm@ornl.gov>
To: Todd Suiter <todd@s4r.com>

Todd,

I agree you should not rely exclusively on a firewall. However, if I place
two nics in a machine, I can effectively by pass the firewall and
eliminating this layer of protection. Hard and crunchy on the inside or
not, they still have access to your internal network without going through
the firewall if you straddle the firewall with a machine with two nics.

I agree with all your points about making sure the inside machines are
hardened as much as possible.

Denny

At 10:06 AM 2/15/2002 -0800, Todd Suiter wrote:
>No, you make your internal network hard and crunchy on the inside as
>welll. This
>is a comoon problem I've seen in MANY places. 'Oh, we have firewall, we're
>fine!". No. If you don't go to the trouble of securing your internal
>network and
>hosts, what good is the security you've done on the outside? All it takes
>is one bad CGI for your pants to be at your ankles.
>
>You have several good options for adding additional layers of security, on top
>of just a firewall. Harden the host(patches, removal of services,etc), ACLs
>on your switchen to allow and disallow certain types of traffic, run an IDS
>or 2, run some form of HIDS, LOOK at your machines on a regular basis(this one
>gets missed a lot). And many more. Most of which fall into the 'best
>practices' that so few actually seem to follow. Things like peer code
>review for new
>cgi apps, research on patches that you are applying, staging your work with
>a prod/stage/dev network, etc.
>
>t
>
>
>On Thu, 14 Feb 2002, Dennis Depp wrote:
>
> > But if the box is compromised, so is your internal network! ;(
> >
> > Denny
> >
> > At 06:30 PM 2/12/2002 +0000, James McGee wrote:
> > >The last place I worked at had a great method...
> > >
> > >Put an addition NIC in them, that way you can keep it separate you can
> also
> > >use this for the admin of the site. In addition, this ensure that backups
> > >do not interfere with network to utilisation to and from the servers!
> > >
> > >Ensure that the servers will not forward packets.
> > >
> > >
> > >----- Original Message -----
> > >From: "Sean Richardson" <sean.richardson@coldnorthwind.com>
> > >To: <security-basics@securityfocus.com>
> > >Sent: Monday, February 11, 2002 6:43 PM
> > >Subject: Backup for win2k boxes in the DMZ
> > >
> > >
> > >Looking for opinions on the best method to back up Win2K web servers in a
> > >DMZ from a single server with a DLT drive. It seams that most backup
> > >programs need netbios enabled in order to backup remote machines and would
> > >much rather not have this enabled even though it would be blocked at the
> > >firewall. Thanks!
> > >
> > >
> > >
> > >
> > >
> > >
> > >---
> > >Outgoing mail is certified Virus Free.
> > >Checked by AVG anti-virus system (http://www.grisoft.com).
> > >Version: 6.0.323 / Virus Database: 180 - Release Date: 08/02/2002
> >
> >



Relevant Pages

  • Re: SBS FTP service getting slammed.
    ... in an IPsec policy to limit FTP access. ... If you are entirely protected by firewall from outside, ... down what comes at you edge machines. ... I will consider your suggestion about the NICs. ...
    (microsoft.public.security)
  • Re: Norton 2005 Int Security, Trend PCcillin or Zone Alarm ???????
    ... > I want security I can run on both machines. ... System overhead is higher than standard firewall applications. ... Symantec products do not remove (uninstall) well. ... Micro Trends PC-Cillan is very good (possibly the best in home network ...
    (alt.computer.security)
  • Re: 2 PCs not visible in net view or network browsing - Why?
    ... > it is the SAME as the Primary DNS suffix -- but this is NOT ... :yes some are public but behind firewall, so only visible to local domain.. ... Between the working machines ... > Are you using a DC for a router (multiple NICs)? ...
    (microsoft.public.win2000.networking)
  • Re: Configuring Windows XP SP2 Firewall for Network-based Scanning
    ... scan machines on my internal network for vulnerabilities that go beyond what ... AV software and the firewall can protect.. ... >> vulnerabilities on client machines. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: install
    ... You just need to set up your network correctly. ... start by running the Network Setup Wizard on all machines (see ... Problems sharing files between computers on a network are generally caused ... by 1) a misconfigured firewall or overlooked firewall (including a stateful ...
    (microsoft.public.windows.vista.installation_setup)