RE: What firewall for small medical research lab



You're going to get some answers that hail back through the holy war of
"OS vs firmware" firewalls.

I worked for a hospital, securing their network. We used the Cisco PIX
line, and it worked well. But, Linux or FreeBSD can do anything the PIX
can do, with less expensive hardware to boot.

That said, in both cases, you have to watch your patches. Cisco has had a
slew of exploits that had to be handled the last few years, just as the
OSs had.

Firmware operating systems simply ship with fewer options that you can
turn on, hence the perception that it's harder to secure the general
purpose OS. Unfortunately, library exploits (buffer overruns, etc) have
more or less tanked the argument.

What you might consider more than firmware vs OS is this: stateful packet
filter firewall (of your choice) as your outer perimeter. Then, put a
proxy-firewall inside of that (Borderware, Raptor, etc). That protects at
two levels of exploits: network and application.

If you have reliable hardware (I'd consider new stuff under warranty) and
the knowledge to build an OS based firewall, do it. If not, make your
choice based on budget and availability of a consultant to help you.

I'll tell you this, the PIX syntax is simpler than IPTables. From what
I've heard, the packet filter engine used by FreeBSD is simpler as well.

Whatever you do, restrict your traffic in both directions (which
eliminates your Netgear and Linksys solutions).

Just some thoughts...

Sincerely,

Bryan S. Sampsel
LibertyActivist.org

-------------------------------------------------------------------------
This List Sponsored by: Webroot

Don't leave your confidential company and customer records un-protected.
Try Webroot's Spy Sweeper Enterprise(TM) for 30 days for FREE with no
obligation. See why so many companies trust Spy Sweeper Enterprise to
eradicate spyware from their networks.
FREE 30-Day Trial of Spy Sweeper Enterprise

http://www.webroot.com/forms/enterprise_lead.php
--------------------------------------------------------------------------



Relevant Pages

  • Re: Netgear DG834 and Multiple Internet IP Addresses
    ... years and back to firmware v1.05.00. ... I don't recall there being an option to disable the firewall on my DG834G ... Added a checkbox to disable the firewall with Network Address ... And the disable firewall option is not shown on the graphic in the older manual:- ...
    (uk.telecom.broadband)
  • RE: can ping but not browse
    ... I have stopped the firewall. ... # are safed from all (security) hazards. ... firewall/bastion host to the internet ... # internet and to an internal network, ...
    (Fedora)
  • Re: Why not use NETBEUI on Windows XP ??
    ... Trusted zones means that firewall rules will be bypassed for any or certain ... not count on netbeui being a defense for such as long as smb connectivity ... while the connection is open. ... > Microsoft Networking components on my network. ...
    (microsoft.public.windowsxp.network_web)
  • Re: Why not use NETBEUI on Windows XP ??
    ... Trusted zones means that firewall rules will be bypassed for any or certain ... not count on netbeui being a defense for such as long as smb connectivity ... while the connection is open. ... > Microsoft Networking components on my network. ...
    (microsoft.public.win2000.networking)
  • Re: Simple Printer Sharing/Networking Question
    ... And all 3 desktop computers are running Windows XP Pro ... We have turned on sharing for the network printers (in association with this ... caused by 1) a misconfigured firewall or overlooked firewall (including ...
    (microsoft.public.windowsxp.network_web)