Re: Proposed Internet Connection Firewall change in WinXP SP2

From: Jon Robertson (jon.robertson_at_medevolve.dontspamme.com)
Date: 12/08/03


Date: Mon, 08 Dec 2003 08:13:05 -0800


> You may be jumping the gun.

True. The article did not, for instance, mention if DCOM was being
modified to be more firewall friendly. This is why I asked where I can
get OFFICIAL information from Microsoft.

> We also do not yet know what might be made
> available for management for ICF from group policy.

Microsoft does not have a history of loudly notifying when steps such
as these need to be taken. If XP SP2 does enable ICF by default even
in a domain environment, and Group Policy administration is available,
Microsoft should very loudly announce that DCOM will be not be
available unless a Group Policy for ICF is created.

If Group Policy administration is not available and ICF is enabled
within a domain, Microsoft should announce very loudly that a default
SP2 installation will break DCOM within the LAN.

> However, I must say that I differ with your assessment of the
> need or not of ICF on individual machines. Most of the worms
> of recent infamy had no problem crossing into corp networks,
> and once there caused widespread damage. Perimeter defense
> is good, but I believe that the only real, long-term solution to
> the issues assuaging the internet will be found by hardening the
> end-point systems.

I'm not a security expert. I'm a developer who is trying desparately
to keep up with the impact of Microsoft's security changes. Please
enlighten me:

If a worm/virus is able to get through a corporate firewall, what would
prevent it from getting through a software firewall like ICF?
Furthermore, if ICF can be configured to truly proteect individual
systems, why can't a corporate firewall be configured to truly protect
the entire corporation?

I agree with steps such as blocking network access from workstations
that are not updated with the most recent security updates.

But a firewall on every workstation on the corporate network? I might
as well disconnect my machine from the network. How many distributed
software solutions exists that would function if every workstation had
an individual firewall? For that matter, without making custom changes
(that are not easy to the end user), I can't share files or printers
from my workstation if I have ICF enabled.

I would hope a completely redesigned ICF would be available before such
drastic steps are taken. One that easily allows the user to custom
configure which services they need access to, similar to the new
configuration of Server 2003.

Thanks



Relevant Pages

  • Re: ZoneAlarm Pro, Sygate Personal Firewall, or built in xp firewall?
    ... ICF monitors outbound ports to know what inbound ports to block/open. ... blocks unsolicited connection attempts. ... connect to the Internet but would not normally purchase a firewall from the ... baseline intrusion prevention mechanism in Windows XP. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Proposed Internet Connection Firewall change in WinXP SP2
    ... Of course a firewall is totally ineffectual against unintelligent ... I would advise you to look at alternatives to DCOM based ... Microsoft MVP ... >> available for management for ICF from group policy. ...
    (microsoft.public.windowsxp.security_admin)
  • SBS 2003 security policy...
    ... I just discovered an amazing new feature of SBS 2003 security policy: ... computers without at least a simple firewall like the one from Microsoft ... they simply disable ICF altogether *while* its connected to the domain. ...
    (NT-Bugtraq)
  • Re: Baseline script (disable services etc.)
    ... > If anyone could give me any tips (as to turning on the ICF and disabling ... Disabling of services: ... Connection Firewall on a connection, ... Note that when using the EnableInternetFirewall/DisableInternetFirewall ...
    (microsoft.public.scripting.vbscript)
  • Re: DCOM 10009 errors on SBS2008 with NAS
    ... what can I do to resolve the DCOM 10009 errors on the SBS2008 machine? ... The DCOM event id 10009 will occur when a client workstation has a miss-configured firewall or other issues affecting its network communications within the domain, for example if the workstation is not managed by an SBS GPO. ... If the workstation is on a different subnet than the SBS server and it is running Windows XP SP2 or higher, the firewall exceptions provided by the SBS group policies will not properly allow the required connectivity. ...
    (microsoft.public.windows.server.sbs)