Re: NBG800 Hackers Test.

From: EricL (Landwehr@national-discount-brokers.com)
Date: 10/06/02


From: Landwehr@national-discount-brokers.com (EricL)
Date: 6 Oct 2002 11:44:09 -0700

We have a final solution to the mess.

DO NOT USE THERE DEFAULT MAIL SERVER! It seems they do not maintain
it. We used a sniffer to monitor the smtp packets to and from our
NBG800. No response from their server just drop connects.

We had to set up a small Unix smtp server that will only allow
connections from our customers IP addresses and it works great. The
alarms work on hackers test and even port scans.

I guess we will keep them because of the price.

"NeoSadist" <neos@dist> wrote in message news:<uprs34hu7eqabc@corp.supernews.com>...
> "EricL" <Landwehr@national-discount-brokers.com> wrote in message
> news:91f1b55f.0210040721.60f2d9f0@posting.google.com...
> > Has anyone use the NBG800 Hackers Test and did it work?
> >
> > I just set up 6 of the Sohoware NBG800 firewalls and none of the
> > hackers test or even if I try to simulate a hacker the alarm Email
> > does not work! This does not give my coustomers a good feeling. The
> > concept was that the hacker alarms were to go to a central email
> > account.
> >
> > I also have a NBG800 running for some time and it use to work. It was
> > so good that when I ran some port scans for an outside source I use to
> > get email alarms.
> > Now I don't!
> >
> > I been talking to another company about trading in theses firewalls
> > for another company maybe Gnat? I just need something just like the
> > NBG800.
> >
> > any comments?
>
>
> I dunno. Are you sure you want all your users notified every time someone
> runs a port scan? And the other thing I would ask is, if this is a software
> firewall and it's installed on all the clients, can your users modify its
> settings? I'd say if so, that isn't good.
> This is my opinion: use a central firewall on the server. Make all of it
> centralized, and have one monitoring station with someone watching the
> inbound and outbound 24/7. That's what I would do. I dunno, maybe I say
> this cause I'm military, and every base has a central network control center
> where all internet comes in and goes out, and it's monitored 24/7.
> I really don't know what to tell you. If you're not satisfied with what you
> got, find some other company. However, if the clients are configured DHCP,
> and the server is the only IP that the internet sees from outside, then that
> may be why they don't see any "attacks", since they'd probably all be aimed
> at the server, since that's the only IP they "see".
> Sorry if this email is a waste of your time.



Relevant Pages

  • Re: NBG800 Hackers Test.
    ... > hackers test or even if I try to simulate a hacker the alarm Email ... > get email alarms. ... > I been talking to another company about trading in theses firewalls ... use a central firewall on the server. ...
    (comp.security.firewalls)
  • Re: CEICW fails at firewall config
    ... Do you or do you not have ISA 2000 or ISA 2004 installed on the SBS server? ... Do you have 2 NICs in the SBS? ... CEICW fails on firewall configuration every time. ... >>> Call to Creating the protected networks access rule returned ok. ...
    (microsoft.public.windows.server.sbs)
  • Re: Recycler security issues on IIS server
    ... > latest upates to the server. ... > like to see the server put behind our firewall, ... other software, install all patches, IISlockdown, URLscan, use the correct ... the procedures you follow may vary depending on your security needs. ...
    (microsoft.public.inetserver.iis.security)
  • Re: ISA SERVER NOT STARTING
    ... I delete the nat/basic firewall and stop and started the RRAS an tried to ... There were no critical events in the DNS Server Log in the last 24 hours. ... An error occurred during logon ... Caller User Name: - ...
    (microsoft.public.windows.server.sbs)
  • Re: For Microsoft Partners and Customers Who Cant Download or Access
    ... to reconfigure the firewall, but to use a static IP on your client ... and to make sure that the DNS server entries on the client are ... Microsoft for msdn2.microsoft.com. ... use a static IP and set the DNS server addresses to the DNS ...
    (microsoft.public.dotnet.general)