Re: Symantic Firewall 100 - Pro/Con Comments Please

From: Markus Kraus (mkr_at_gmxpro.de)
Date: 03/03/04


Date: Wed, 03 Mar 2004 11:40:23 -0800

On Wed, 03 Mar 2004 16:22:48 GMT, Lars M. Hansen wrote:

>Cons:
> - if outbound access is restricted, then there's very limited which
>services can allowed out. About 12-14 services are predefined (http,
>pop3, smtp, dns, ftp, ...), and you can add an addition 5 custom TCP and
>5 custom UDP ports (or ranges).

- and, you can only allow a certain port in general (meaning, for all
addresses). For some services (like smtp, pop3, or vpn), I prefer to
limit the port usage to a fixed list of service providers. (For
example, I hope to prevent potential viruses that make it into my home
LAN to send out mass emails through anonymous remailers). Therefore, I
replaced my Symantec 100 at home with a SonicWall SOHO3.

I also didn't like the logging capabilities of the Symantec 100. It
appeared that when the PC that collects the syslog data was turned
off, the Symantec all of a sudden stops sending the syslog messages.
So even when the PC comes back to life, and the Symantec still has its
IP address listed in the "syslog" field, the Symantec still doesn't
send the syslog messages. I had to go to the Symantec config web site,
and press "save" at the syslog settings in order to revoke it.

That said, I also disliked that the web interface is only HTTP, not
HTTPS.

So, even for my personal home network, I found the Symantec 100
insufficient.

>Lars M. Hansen
>www.hansenonline.net

BTW, I like your web site! The other day, I was curious so I clicked
on that link in one of the messages you posted, only to find out that
I had your site already listed in my "list of cool sites" (not knowing
that YOU're the man behind it).

Best regards,
Markus



Relevant Pages

  • Re: Automatic email relay agent?
    ... set port 587 for SMTP on the server side, then it may work with Symantec ... Generate the certificate files needed for TLS Fedora Postfix implementation: ...
    (Fedora)
  • Re: Port 80
    ... deshalb kann ich auch keinen abschalten. ... Der Symantec Security Scan sagt mir aber, das Port 80 und 443 offen sind, ... meldet Symantec security check keine offenen Ports ...
    (microsoft.public.de.security.heimanwender)
  • Re: Port 80
    ... Das ist ein Internettelefon das ich nutze ... Symantec meldet die Ports aber nur dann offen, ... >> Router ins Internet, meldet Symantec security check keine offenen Ports ... > dort ein Netstat -baon ab und sieh nach, welche Prozesse auf Port ...
    (microsoft.public.de.security.heimanwender)
  • RE: OWA display incomplete when accessed from a customers dmz
    ... The site is using Symantec but doesn't have WebDav defined. ... >> At the client sites data is allowed through port 80. ... >> Joe Kelly ...
    (microsoft.public.exchange.clients)
  • How interesting... No L0phtCrack outside the US and Canada...
    ... Symantec refuses to sell audit tool outside the US ... Get breaking Security news straight to your desktop - click here to find out ... has gone and the product has not appeared on the Symantec web site. ... Symantec's restrictions recall the dark days of the crypto wars when users ...
    (soc.culture.polish)

Quantcast