Re: firewall test and NAT
- From: "Twayne" <nobody@xxxxxxxxxxxxxxxxxxx>
- Date: Fri, 8 May 2009 17:10:32 -0400
A well written response, Leythos. Except I'd say "ignorant" instead of
"stupid" in your second para, otherwise it's spot on IMO.
The reason I say ignorant is the main targets of the
spammer/scammer/social scoundrels often hook the newbie and
inexperienced who haven't yet encountered the problems or had anyone to
lead them to the right areas for Security. There are so many different
things for them to learn, even as they start to pick up on security,
they often go right on inviting the malware in. The anonymity of the
'net sucks.
Twayne
Leythos wrote:
In article <OaNoS8A0JHA.5764@xxxxxxxxxxxxxxxxxxxx>,
ToddAndMargo@xxxxxxxxxxx says...
What triggered my question is a customer who relies on NAT (only,
no firewall), and he is constantly getting tagged with one
v1rus or another. I am trying to get him off IE, get a
standardized decient antivirus, software firewall, and a *real*
firewall.
NAT has nothing to do with him getting malware on his system.
With all of the issues that have been in the media, anyone getting
malware has just got to be stupid, at least for the most part.
If you want to secure a business, since they will never do the right
thing, at least with all my years of dealing with businesses....
Install a firewall that allows content filtering - block EXE, DLL,
etc... from all connections except the Server or a IT Admin's
workstation. You also AV/content filter SMTP, FTP, HTTP, HTTPS
sessions and you block all IN/OUT connections that are not explicitly
needed for business (which should be the standard for any firewall
solution)
Install a managed, corporate type AV solution - like Symantec End
Point Protection - don't give users control of the settings or the
ability to disable it on their workstations.
Install IE settings via Group Policy that the users can't change...
Make all computer users LOCAL USERS, NOT Local Admins....
IE works fine, just make all updates automatic install.
With the above ideas and a little more, I've managed to secure
networks all over the USA and not had a single managed network
compromised in my entire history.
.
- Follow-Ups:
- Re: firewall test and NAT
- From: Leythos
- Re: firewall test and NAT
- References:
- firewall test and NAT
- From: ToddAndMargo
- Re: firewall test and NAT
- From: John John - MVP
- Re: firewall test and NAT
- From: ToddAndMargo
- Re: firewall test and NAT
- From: John John - MVP
- Re: firewall test and NAT
- From: ToddAndMargo
- Re: firewall test and NAT
- From: Brian A.
- Re: firewall test and NAT
- From: ToddAndMargo
- Re: firewall test and NAT
- From: John John - MVP
- Re: firewall test and NAT
- From: ToddAndMargo
- Re: firewall test and NAT
- From: Leythos
- firewall test and NAT
- Prev by Date: Re: Enable administrative privileges
- Next by Date: Re: Static update shield on Turn Off button
- Previous by thread: Re: firewall test and NAT
- Next by thread: Re: firewall test and NAT
- Index(es):
Relevant Pages
|