Re: Host-Base Firewall



All,
Firewalls are packet control devices. They do little more than control the flow of traffic into and out of your network. Some of them contain "defensive" capabilities such as IPS. Those defenses make decisions based on the nature of the traffic. Those decisions aren't as accurate as they should be because the very medium from which they are forming "opinions" is flawed. Traffic can be spoofed/forged/manipulated, so how can one trust it.

Security is more of a process than anything else. It is enforced by policies, procedures, and the people using technology. Security can not be found via hardware. This is a bit philosophical, but I can back this up if anyone doesn't understand my perspective.

Regards,
Adriel T. Desautels
Chief Technology Officer
Netragard, LLC.
Office : 617-934-0269
Mobile : 617-633-3821
http://www.linkedin.com/pub/1/118/a45

Join the Netragard, LLC. Linked In Group:
http://www.linkedin.com/e/gis/48683/0B98E1705142

---------------------------------------------------------------
Netragard, LLC - http://www.netragard.com - "We make IT Safe"
Penetration Testing, Vulnerability Assessments, Website Security

Netragard Whitepaper Downloads:
-------------------------------
Choosing the right provider : http://tinyurl.com/2ahk3j
Three Things you must know : http://tinyurl.com/26pjsn


Murda Mcloud wrote:
Shouldn't that be Firewalls != Security

But (Firewalls + patching +...+ lots of other stuff) ~ Security (if not done
well) ; or
(Firewalls + patching +...+ lots of other stuff) tends towards Security if
that is done well.






-----Original Message-----
From: listbounce@xxxxxxxxxxxxxxxxx [mailto:listbounce@xxxxxxxxxxxxxxxxx]
On Behalf Of Adriel Desautels
Sent: Thursday, May 29, 2008 6:29 AM
To: Mohamed Farid
Cc: 'Shawn A. Corrello'; security-basics@xxxxxxxxxxxxxxxxx; security-
basics-return-49273@xxxxxxxxxxxxxxxxx
Subject: Re: Host-Base Firewall

Windows firewalls != security.

Regards,
Adriel T. Desautels
Chief Technology Officer
Netragard, LLC.
Office : 617-934-0269
Mobile : 617-633-3821
http://www.linkedin.com/pub/1/118/a45

Join the Netragard, LLC. Linked In Group:
http://www.linkedin.com/e/gis/48683/0B98E1705142

---------------------------------------------------------------
Netragard, LLC - http://www.netragard.com - "We make IT Safe"
Penetration Testing, Vulnerability Assessments, Website Security

Netragard Whitepaper Downloads:
-------------------------------
Choosing the right provider : http://tinyurl.com/2ahk3j
Three Things you must know : http://tinyurl.com/26pjsn


Mohamed Farid wrote:
I don't want to depend on Windows Firewalls ...
I need a 3rd party software ...

Yes we are using Windows on our laptops ( Windows 2000 )

Mohamed Farid ,CISSP,CCSP,S+
m.farid.shawara@xxxxxxxxx


-----Original Message-----
From: Shawn A. Corrello [mailto:shawnc@xxxxxxxxxxxxxxxxxx]
Sent: Wednesday, May 28, 2008 7:57 PM
To: Mohamed Farid
Cc: security-basics@xxxxxxxxxxxxxxxxx;
security-basics-return-49273@xxxxxxxxxxxxxxxxx
Subject: Re: Host-Base Firewall

What OS are the laptops? Windows Firewall is free and can be managed
and
administrated centrally via Group Policy...not going to help if you're
laptops are Linux or Macs though.

On Wed, 28 May 2008, Mohamed Farid wrote:

Dear All ,,,

Any recommendation for a cost effective Host-Base Firewall to be
installed
on my remote users' Laptops - and to be managed and be administrated
centralized by my security team ?

Thanks ,,,
Mohamed Farid ,





Relevant Pages

  • Re: Defense in Depth
    ... What is meant by "layers" of security, is this: the entry points that must be ... Physical Layer - Physical access to the resources. ... attacks and other attacks that go after the software itself. ... "layer" in one long chain (lots of firewalls). ...
    (Security-Basics)
  • RE: Wireless Security for Home Users
    ... for most home users to create and/or manage 2 firewalls and a DMZ. ... As with most network security, ... investigate additional security features available from the WAP ...
    (Security-Basics)
  • RE: [Full-Disclosure] RE: MS SQL WORM IS DESTROYING INTERNET BLOCK PORT 1434!
    ... > 1) I don't trust MS products for security related tasks. ... firewalls running on NT? ... necessary steps to mitigate the risk and protect yourself. ... We still had six boxes hit. ...
    (Full-Disclosure)
  • RE: IDS is dead, etc
    ... Most firewall logs are just as tough to decipher as IDSs. ... Automated security analytics is a tough animal I don't care what the system. ... firewalls and IDSs, not just IDSs. ... There is no solution to these problems, therefore IDS is dead and we ...
    (Focus-IDS)
  • RE: [Full-Disclosure] Re: Microsoft Security, baby steps ?
    ... You can have firewalls guarding the outside, ... the network? ... We also need software vendors to ... stop giving lip service to security and start actually implementing it. ...
    (Full-Disclosure)