Re: OT-- Low power, quiet least expensive firewall option



On Wed, 27 Dec 2006, in the Usenet newsgroup comp.security.firewalls, in article
<459226AB.95C78040@xxxxxxxxxxxx>, OSbandito wrote:

Moe, This is a marginally related question. My only experience with
firewalls has been the use of a router (basic functions) and a software
firewall to augment. Please give me your opinion on using this simple
combination to protect and administer a Freenet (or similar) server.

My personal preference would be for a simple box connected to the
Internet side of things that only permits those connections INBOUND
that the administrator wants to allow. If you are providing a web
server, then someone connecting to your Internet address should ONLY
be able to connect to port 80 and/or 443 or where ever you are running
that server. There's no need for them to connect to your gopher server,
or finger, or telnet, or SSH or any other port, period. You can do
this connecting the server directly, (and allowing _your_ administrative
connection via a different interface), depending on your skill level.

Do you think this would be adequate or would I be better off learning
how to build a proper firewall? ~Thx

Two things - know how to build a proper _server_ (which mean one that
has the needed applications and no more than that), _and_ know how to
build the firewall. The first point is important - if it's not
installed, it can't be exploited. Our "public" servers all run from
'read-only' media as an added precaution, and any volatile data is mounted
'noexec'. It's much harder to exploit that way. Anything uploaded from
"outside" gets dropped into a directory with d-w-rwx--- permissions - the
'w' to allow the data to be written by a user with NO other permissions
anywhere else on the file system, and the 'rwx' to allow the data to be
removed by a cron job by a group with only one user and transferred to
a quarantine area where outsiders have no access. The 'un-trusted' user
(often 'guest' but I've also seen them named 'intruder' or 'hostile')
only belongs to a separate group that is otherwise unused. This avoids
access through the 'others' permissions (-------rwx) that is granted if
you are not the owner or a member of the group.

note: will likely run Solaris

For the server, this would be fine. Use the O/S you are comfortable with,
the one that you can secure. As a combined server and firewall, I'd be
a little less enthused, but that's mainly because I don't "know" the
firewall capabilities as well as I'd want to. For a firewall alone, I'd
usually recommend an O/S designed for this function rather than a general
purpose design. I mentioned using Linux on my home firewall, and it's a
stripped version using a local compile. I'm using that simply because I
have experience with that O/S and feel comfortable with it. I would
never consider using an 'out-of-box' 'popular' distribution simply
because that 'out-of-box' install has much unneeded stuff/features/etc.

Old guy

.



Relevant Pages

  • Re: CEICW fails at firewall config
    ... Do you or do you not have ISA 2000 or ISA 2004 installed on the SBS server? ... Do you have 2 NICs in the SBS? ... CEICW fails on firewall configuration every time. ... >>> Call to Creating the protected networks access rule returned ok. ...
    (microsoft.public.windows.server.sbs)
  • Re: Recycler security issues on IIS server
    ... > latest upates to the server. ... > like to see the server put behind our firewall, ... other software, install all patches, IISlockdown, URLscan, use the correct ... the procedures you follow may vary depending on your security needs. ...
    (microsoft.public.inetserver.iis.security)
  • Re: [opensuse] Two NICs, one connected, Ping Both...?
    ... Server is behind a Router, and the Router is doing Port Forwarding. ... Only one of these RJ45 Ports is connected, but I can Ping them both. ... Not counting completely broken firewall rules. ... Start by turning off the firewall, double-checking that you are running ssh, and connecting from a localhost. ...
    (SuSE)
  • Re: ISA SERVER NOT STARTING
    ... I delete the nat/basic firewall and stop and started the RRAS an tried to ... There were no critical events in the DNS Server Log in the last 24 hours. ... An error occurred during logon ... Caller User Name: - ...
    (microsoft.public.windows.server.sbs)
  • Re: For Microsoft Partners and Customers Who Cant Download or Access
    ... to reconfigure the firewall, but to use a static IP on your client ... and to make sure that the DNS server entries on the client are ... Microsoft for msdn2.microsoft.com. ... use a static IP and set the DNS server addresses to the DNS ...
    (microsoft.public.dotnet.general)

Quantcast