ISP Security Suggestions

From: Vernon (Vernon@b2unow.com)
Date: 03/24/02


Date: Sun, 24 Mar 2002 10:05:57 -0500
From: "Vernon" <Vernon@b2unow.com>
To: "security-basics@securityfocus.com" <security-basics@securityfocus.com>

I have a Windows 2000 Advanced Server setup with a T1 and a Cisco Router
2600 that is managed by our T1 provider. I've also have deployed the
latest version of IceCap (the network version of Black Ice) blocking all
ports, other than those needed to support our email server, 25 and 110.
Furthermore, I've blocked every port using Microsoft's IPSec, again
excluding 25 and 110, and naturally we keep up-to-date with all the
latest patches from Microsoft.

My question is, as this machine is not setup using a Proxy server nor do
I have a hardware firewall does anyone see a real need to purchase a
hardware firewall? Or furthermore a proxy server? I understand that this
would be the ideal situation and every ounce of effort you make a hacker
go through limits their ability to hack into my network, but doesn't it
seem a little redundant to add these extra steps? Does anyone feel that
these extra steps, extra effort and added cost are justified?

Any suggestions and or comments would be greatly appreciated.

Thanks



Relevant Pages

  • Re: Blocking sites fails
    ... I have a hardware firewall, ... Single NIC mode on my file server, created a mess of rules (cool that you ... BUT, when I remove the proxy information from my connection settings, I can ... I would recommend setting a nice solid GPO that both sets the Proxy Settings ...
    (microsoft.public.isaserver)
  • Re: Exchange will not send messages with attachments
    ... I have tried both with DNS and smarthost. ... I have no hardware firewall, straight through a vigor router, but will ... Cisco pix firewall with the SMTP filtering enable ... data following the Microsoft Exchange Server XEXCH50 command. ...
    (microsoft.public.windows.server.sbs)
  • Re: Exchange will not send messages with attachments
    ... I have no hardware firewall, straight through a vigor router, but will ... Cisco pix firewall with the SMTP filtering enable ... data following the Microsoft Exchange Server XEXCH50 command. ... Open Exchange System Manager. ...
    (microsoft.public.windows.server.sbs)
  • Re: SBS 2003 Premium ISA 2000
    ... How many nics in the server? ... the basic NAT/Firewall will protect your ... If 1 and no hardware firewall, ...
    (microsoft.public.windows.server.sbs)
  • Re: Forged Source Address
    ... protected by both a hardware firewall and an integrated antivirus suite. ... > see if it adds up to the total amount of disk space you have. ... I have check our server with the ORDB and other relay testers ...
    (comp.security.misc)