Re: LAN Security

From: Karl Levinson [x y] MVP (jamescagney90210@excite.com)
Date: 10/19/02


From: "Karl Levinson [x y] MVP" <jamescagney90210@excite.com>
Date: Sat, 19 Oct 2002 10:31:29 -0400


"WillieC" <williec00@hotmail.com> wrote in message
news:6d4601c276e6$6cd02090$37ef2ecf@TKMSFTNGXA13...
> I am the new network admin for a small business with 2
> Win2K Servers (only one AD and it is PDC emulator), one
> Small Business Server 4.5(BDC) and about 25 workstations.
> I just accepted this position and there is NO security on
> the network. We have internet access running through a
> VINA router. The router is 10.0.0.1 and that is my
> gateway for all computers. Can anyone suggest a security
> approach? I don't know a lot about firewalls but from
> what I gather it needs to sit on a machine that is the
> router and gateway. I need an inexpensive, yet secure way
> to monitor and lock down the network. PLEASE HELP!!!

There's a lot to learn to make a network secure.

Inexpensive firewalls include Linksys, Netgear, Netscreen, or you can
download and build your own linux / BSD firewalls that boot from a single
boot floppy or CD on an old 486 PC, such as ClosedBSD, IPCop, Smoothwall,
Gibralter, etc. Those would be free. The firewall would probably go behind
your router though that would require some changing of IP addresses and
subnets on your router [unless you set up a linux firewall to be a
transparent bridged firewall / ethernet bridge, which doesn't require IP
address changes]. Linux may sound scary to someone not familiar with it,
but some of the solutions mentioned are menu or GUI software aimed at SOHO,
home users and beginners.

You also want to secure the machines on your network. All
service packs and patches installed, configured using one or more hardening
checklists
such as the ones at www.microsoft.com/technet/security and www.nsa.gov etc,
antivirus that downloads updates daily, run vulnerability assessment scans
such regularly such as MBSA from www.microsoft.com/download and the free
languard network scanner from www.gfi.com, you might also want to enable
logging and auditing, use a file change checker like Languard file integrity
checker [free] at www.gfi.com under the white papers section, etc etc.



Relevant Pages

  • Re: [fw-wiz] Firewall routing thought...
    ... networks that the firewalls are protecting, ... and let the router sort out what networks are ... >>Your network layout isn't really clear from your email, ... >>you make a change in broadcast domains, the router is going to be involved. ...
    (Firewall-Wizards)
  • Re: Ask EU Technical Section: Networking questions
    ... I have just added a new lapdog to my household and so needed to set up a wireless network, so that it could share the broadband connection with the main PC. ... The router is a Belkin N Wireless Modem Router. ... You need to set the software firewalls on each PC to allow the local network to connect to them. ... If you can't Share the folder, you will need to enable File Sharing for the machine as a whole. ...
    (uk.media.radio.archers)
  • [fw-wiz] Firewalls v. Router ACLs
    ... used firewalls to protect our part of the network from network ... 100% successful and we have not been impacted by the numerous network-borne ... We are now being pressurised to remove the firewalls by the rest of the company. ... A secondary argument is cost - the router is seen as a one-off purchase ...
    (Firewall-Wizards)
  • RE: HSRP with load balancing on a Cisco IOS based firewall
    ... Can I implement MHSRP across IOS based firewalls on Ciso routers? ... Split the network behind the Firewall into subnets say Network A and network ... Network A has router X as its primery and router Y as its secondary. ... My prelimnary research on HSRP gives me the understanding that in an HSRP ...
    (Security-Basics)
  • RE: [fw-wiz] Firewalls v. Router ACLs
    ... people to take in consideration in network design and layout. ... here and the old firewalls list often emphasized an approach that avoided ... The logging alert features alone turn this layer into a IDS as ... > An appropriately sized router will not have any performance problems. ...
    (Firewall-Wizards)