Re: sbs2003 and Zone Alarm

From: CZ (CZ_at_no99spam.com)
Date: 04/01/04


Date: Wed, 31 Mar 2004 21:25:51 -0800

Javier:

>> You do realize that Sygate PE v5.5 is not a server product? It is a
*personal* firewall... that's enough to deter me from using it.

And do you consider R&RA's Basic Firewall to be more than a personal
firewall?
Seriously, dnload Sygate and review it. It is a very impressive product.
For a small setup with a constrained budget, I could see using SBS2k3 Std
behind a NAT-router with Sygate, as opposed to no host based firewall at all
with a NAT-router. Sygate gives you application control, and you can
schedule port status (open/closed-stealth).

>> In any event, what do you mean by host based control? By IPs or ports?

The product runs on the host and is designed to protect the host. IMO, ISA
on top of SBS2k3 is not designed to "product" the host, as ISA is designed
to be a perimeter firewall that screens the network traffic. A good host
based server class firewall is BlackICE for Servers ($299).

>> IMHO-> If I want a real firewall I get SBS2k3 Prem Ed... so I can install
ISA :-)

IMO, a stronger security setup would be to buy ISA separately, and set it up
as a perimeter device, not on top of SBS2k3.
And, SBS2K3 has too many services running on it as it is.



Relevant Pages

  • Re: Host Computer with ICS cannot be accessed
    ... I have the Main (Host) computer with XP SP1 which is the ICS computer on a ... firewall settings, not that I've found so far, but I'll keep looking. ... >>connection, I can check or uncheck the firewall setting to allow others on ... Is there a way I can tell my Host server to allow the Client ...
    (microsoft.public.windowsxp.network_web)
  • Re: Host Computer with ICS cannot be accessed
    ... I have the Main (Host) computer with XP SP1 which is the ICS computer on a ... firewall settings, not that I've found so far, but I'll keep looking. ... >>connection, I can check or uncheck the firewall setting to allow others on ... Is there a way I can tell my Host server to allow the Client ...
    (microsoft.public.windowsxp.network_web)
  • Re: One computer cant see the other.
    ... I'm not sure I'm doing this right Steve, but on the command prompt at my host ... command prompt on my host machine and my client machine when I ping the host. ... network of two computers. ... The most likely problem is that a firewall (Norton, McAfee, ZoneAlarm, ...
    (microsoft.public.windowsxp.network_web)
  • RE: [fw-wiz] Vulnerability Response
    ... >> management effort scales with the number of hosts. ... It scales non-linearly if the problem area is well-defined. ... Now - if you're gonna make a firewall policy for 10,000 desktops ... When someone talks about doing mitigation at the host level, ...
    (Firewall-Wizards)
  • RE: Securing a Local Network
    ... attacker that has broken into one host to hop among the other hosts. ... If you have a central firewall acting as a choke point, ... computers to go out over non-essential ports, ... > interaction with one of our expert instructors. ...
    (Security-Basics)