Re: Requesting security tips on network setup

From: those who know me have no need of my name (not-a-real-address@usa.net)
Date: 04/07/02


From: those who know me have no need of my name <not-a-real-address@usa.net>
Date: Sun, 07 Apr 2002 05:29:33 -0000


<3CAF861E.2090801@hotmail.com> divulged:

>I've just finished setting up my small business network and was hoping
>that someone could maybe suggest some tips to make my network as
>invisible to the outside world as I can. I'm not naive, I know that if
>someone really wants to get in that they will but I at least don't want
>to have my network sitting with a "Come and crack me" sign on it's back....
>I'm going to work from the outside (Internet) in;

invisible is the wrong thing to shoot for, protected is what you want.
why? because you are forwarding ports you won't be invisible no matter
what else you do. since you are using a napt router you have a fair
amount of safety, but the three services you are forwarding will have to
be watched. all of the daemons you've mentioned have had exploits
against older versions, and there's no reason to think that exploits
won't be found for the current versions (at some point), so vigilance
(watch your logs, active and/or passive monitoring, and pay attention to
security notices) will be the key to keeping things running well.

make a plan for what you'll do _when_ (not if) you are cracked. there's
not all that much that really needs to be done, in terms of steps. each
step might mean lots of work though. why? so that you are calm when it
happens.

btw: don't dismiss the imap server from your mind, just because it's
non-critical. it's inside your network, so if it's broken into it can
be used to do all sorts of other unpleasant things.

>I've also set my router up to block ICMP requests as well.

this is up to you, but i find it's not all that useful to do, i.e.,
what do you think you are accomplishing? preventing your isp from being
able to check the health of your service? preventing load balancers from
providing the "closest" ip address for a cached service (e.g., yahoo)?
preventing ... ?

>Can anyone give me any extra suggestions or is that about all I can do?

port filters on each machine in case the router "fails." enable the
router's remote syslog support, and capture that on some system,
preferably not a system providing any other services. snort to watch
the traffic you allow in. subscribe to mailing lists or monitor web
pages for updates to any software you use and for your router.

but also, relax.

-- 
bringing you boring signatures for 17 years



Relevant Pages

  • Re: Using Remote Desktop From an SBS Domain
    ... After I thought about needing 3389 forwarded on my router to allow me to ... Remote Desktop "out" from a workstation on my SBS network to a host XP ... Hopefully next week I can attempt a connection while my ISP watches the ...
    (microsoft.public.windows.server.sbs)
  • Re: Linksys NAS200 Network Storage adapter
    ... The only two wireless network settings that are of any consequence are the SSID and the encryption method and password. ... either click the "Print Network Settings" button on the final screen of the Wizard or simply access the appropriate XML file and get at them that way and then use the information to configure the router manually as I explained earlier. ... I've read thru some of the MS web site on that product and it appears to do everything a NAS will do plus other cool features, such as, with an xbox360 with the wireless adapter, I can stream my video/pics to my TV for family viewing. ...
    (microsoft.public.windowsxp.network_web)
  • Re: OSPF routes not in routing table
    ... Here's the output of "sh ip ospf database router", ... "(Link Data) Router Interface address: ... Link connected to: a Stub Network ... Number of TOS metrics: 0 ...
    (comp.dcom.sys.cisco)
  • Re: Host Computer with ICS cannot be accessed
    ... You read my mind on the router thing. ... My home network is a piece of cake... ... >>firewall settings, not that I've found so far, but I'll keep looking. ... and we couldn't get file sharing working until ...
    (microsoft.public.windowsxp.network_web)
  • Re: 2 pc network - cant see host files from pc 2 on pc 1
    ... Assuming that you have firewall protection via your internet router try ... workgroup because it will be needed for the network to work correctly. ... see if you can access TCP ports 139 and 445 on computer one of which at ... permissions. ...
    (microsoft.public.windowsxp.security_admin)

Quantcast