Re: 2 Completely separate companies using same server room

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



"BSweeney" <BSweeney@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:5A5BB290-E3EA-41E4-8694-0D14C3BFE1E7@xxxxxxxxxxxxxxxx
With all due respect Phillip, I couldn't disagree with you more. We
aren't
talking about a home office, or a converted coat closet, but an actual
server
room shared by two different companies.

And that is exactly what I am talking about as well.

While cabling is absolutely important
for the sake of keeping things organized and manageable, it provides no
actual security by itself,

Of course it provides security. If two networks are not on the same
cabling, then there is no physical connection between the two systems then
there is no way possible for them to communicate,...you can't get any more
secure than that.

post. The seperate racks with lockable doors provide a reasonable level of
physical security in a room where two IT teams will be working on
connected
networks.

Racks such as that for physical security are perfectly fine,...I didn't tell
him to *not* use them,...but I was dealing with the actual networking. If
the two networks are on the same physical cabling then it isn't going to
matter how many lockable racks they are in because the door would not even
need to be opened to get to the machines.

At the packet level, cables by themselves provide no security
without propper subnetting, routing configuration, and firewall rules.

With two separate physical cabling systems there is no subnetting, routing
configuration, and firewall rules. At least not in the context of the two
networks working together because they simply never touch each other. I'm
looking at the bigger picture which includes the entire building, not just a
rack or two.

I'm not really sure what you were driving at here,

Appearantly, that's true.

I'm sorry, but it sounds like you just made a knee-jerk reaction to what I
said because you thought I was trying to stomp on your post and didn't
really think about what I said. I wasn't stomping on your post, I was
dealing with the context and direction that the thread was moving in.

--
Phillip Windell
www.wandtv.com

The views expressed, are my own and not those of my employer, or Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------
Understanding the ISA 2004 Access Rule Processing
http://www.isaserver.org/articles/ISA2004_AccessRules.html

Troubleshooting Client Authentication on Access Rules in ISA Server 2004
http://download.microsoft.com/download/9/1/8/918ed2d3-71d0-40ed-8e6d-fd6eeb6cfa07/ts_rules.doc

Microsoft Internet Security & Acceleration Server: Partners
http://www.microsoft.com/isaserver/partners/default.asp

Microsoft ISA Server Partners: Partner Hardware Solutions
http://www.microsoft.com/forefront/edgesecurity/partners/hardwarepartners.mspx
-----------------------------------------------------


.



Relevant Pages

  • Re: NASA Security Audit
    ... I would suggest using redhat linux on this box, ... firewall rules. ... into - it can effectively make it near impossible to intrude on your server ... I hear he is a well known security expert ...
    (Security-Basics)
  • Re: Security conserns with RWW and OWA
    ... > Microsoft Small Business Server and Security: It's All About Risk ... >>I am a SMB consultant who looks after a number of different sized networks ...
    (microsoft.public.windows.server.sbs)
  • Re: ipfilter or ip xyz filtering security question
    ... > Do you think it is necessary to enforce security on a freebsd server and use ... already uses other forms of security. ... any more secure just because it's behind the firewall. ... There are many ways to write your firewall rules. ...
    (comp.unix.bsd.freebsd.misc)
  • Re: Everyone needs to know
    ... Tracker wrote: ... > aren't using a Virtual Private Network, Mail Server, FTP Server, TCP ... Without the above security, the malicious hackers are ... traded everyday on IRC Networks like EggDrop. ...
    (alt.computer.security)
  • Re: Incorrect server name
    ... There is no primary WINS server defined for this adapter. ... Broadcom BCM5708C NetXtreme II GigE (NDIS VBD Client) ... Client for Microsoft Networks ...
    (microsoft.public.windows.server.general)