New install question

From: Jeff (anonymous_at_discussions.microsoft.com)
Date: 05/28/04


Date: Fri, 28 May 2004 07:31:39 -0700

Hi Bob,

In my experience it's best to have a separate firewall
(either an appliance type or another computer), in
addition to your DSL router and your SBS server. This
offers a better level of protection and ensures that
attacks that possibly bring your firewall down (and cut
you off from the outside) do not corrupt anything on your
SBS server itself. Just get your firewall back up and
that's that.

I'd recommend a netscreen XP Firewall appliance for a
small to med. sized network (<50 machines)- I'm using one
and it's rock solid. Symantec also makes an appliance
type firewall that is cheaper, but a little harder to
configure. Google either of these and you'll get lots of
info.

-Jeff

 
>-----Original Message-----
>Current config: Workgroup
>Internet: dsl via cayman/netopia router, firewall enabled
>
>Soon to be installing: SBS std server
>
>My question is, is there a preferred setup for my nic
configuration on my
>server.
>any advantages to running the firewall on the server (2
nics) vs using my
>router and 1 nic on the server?
>
>Is there is a link I can go to to read up on this?
>
>thanks in advance
>
>
>.
>



Relevant Pages

  • Re: SBS Premium installed - Some configuration questions...
    ... I prefer to have my server handle the DHCP. ... The SBS server will leave before the firewall hardware will, ... internet if I had not had a hardware firewall in place ... But it still exposes the SBS server to possible attack. ...
    (microsoft.public.windows.server.sbs)
  • Re: Internet on nodes
    ... And the SBS server is handling the DHCP service for the entire network, ... Merv Porter [SBS-MWP] ... Do I have to open some ports in the firewall? ...
    (microsoft.public.windows.server.sbs)
  • Re: LINUX Firewall
    ... I was not implying that LINUX was a better, ... My concern is that the SBS server is connected directly to ... firewall would be a more secure setup. ... My SBS server is fully patched as well as all workstations. ...
    (microsoft.public.backoffice.smallbiz2000)
  • RE: Disable ICMP redirects
    ... What it sound like you need to do to have the firewall only see the server is ... > The sonic is complaining that all its 10 lan licenses are ... > So it seems to me that the sbs server is doing icmp ...
    (microsoft.public.windows.server.sbs)
  • Re: companyweb cannot route over internet
    ... If there is only one NIC installed on the SBS server box, ... provides Windows basic firewall on the server box and client computers. ... This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)