Re: best network setup?



Hah! yes I did actually put 'proper' in quotes so it wasn't taken literally.
Maybe I'll rephrase to 'a more traditional descrete firewall implemenatation'.

I would say that if ICSA dont test something doesn't mean its no good - it
means they haven't tested it(!) Looking at the list, their tested products
aren't that up to date but its a good place to validate ones choice. I only
recommend Netscreen as it happens - but, whew - close one; I used to use a
shoe box holding al dente sphagetti with a hole at each side as my firewall.

As I say, I'll post this as a separate question to see if there are any
'proper' (!)explanations to favour one method as compared to another.


"SuperGumby [SBS MVP]" wrote:

> 'proper' firewall eh?
>
> Is this 'proper' firewall you're referring to certified to the same level as
> ISA? You can check here
> http://www.icsalabs.com/html/communities/firewalls/newsite/cert2.shtml
> if your firewall ain't listed it ain't good enough.
>
> ISA can only act as a firewall in a minimum 2 NIC configuration. (as can any
> true firewall)
>
> MOST large companies run a multilegged firewall. Internal (leg 1), external
> (leg 2) and optional DMZ (leg 3).
>
> In SBS we break a basic creed of firewall implementation, hosting the
> firewall on the Domain Controller. I know of no security incident which can
> be traced to this being the basic fault. ISA on SBS has proven itself a
> reliable and safe option.
>
> "Aus" <Aus@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
> news:EB710370-F1BA-493A-A2A8-C61DCDA85A75@xxxxxxxxxxxxxxxx
> >I think you find may SBS people automatically say 2 nics but I think this
> >is
> > a messy approach - no large company would do things this way so the
> > hardware
> > firewall/router to a single NIC tends to be the preferred option for me. I
> > have yet to see the actual advantages of 2 nics over a 'proper' firewall -
> > it
> > seems to complicate things and you dont want that with SBS. Maybe we need
> > to
> > be enlightened?! (perhaps a separate thread for that question..)
> >
> > Not sure if nic teaming is relevant - you could never saturate a 100Mb
> > link
> > continuously on most networks - let alone a 1Gb link - most networks dont
> > run
> > like that.
> >
> > "Brian Murphy" wrote:
> >
> >> Hi,
> >>
> >> I just purchased a server along with a copy of Microsoft SBS 2003 STD
> >> edition. I would like to know what the best network setup is for SBS??
> >> Should I go with 1 or 2 nic cards in the server? Should I use a router?
> >>
> >> Thanks in advance!
> >>
> >>
> >>
>
>
>
.



Relevant Pages

  • Re: Windows updates unavalaible
    ... Most of the recent exploits are stopped by a firewall. ... Windows Update. ... You can buy a computer from a shop with no updates of any kind, ... Do NOTHING ELSE until all Critical Updates are installed and a proper ...
    (microsoft.public.security.virus)
  • Re: HELP! hackers at the gates!
    ... What a firewall ... ensure that the proper protocols are in use on the proper ports, ... IDS is helpful, but not a panacea by any means. ...
    (microsoft.public.win2000.security)
  • RE: what should I do when....
    ... firewall logs, from a specific ip based in Canada, the log ... it seems that someone is trying to initiate a connections, ... and dns whois query both of those point to ip and host in Canada it ... network.....could anyone advice me what's the proper course of actions in ...
    (Security-Basics)
  • Re: Great Firewall/Australia censorship proposal
    ... how do you suppose the traffic appears to a firewall? ... properly secured network? ... Calling an illegal alien an "undocumented worker" is like calling a ... spam999free@xxxxxxxxxx (remove 999 for proper email address) ...
    (comp.security.firewalls)
  • Re: Stop Exchange from sending mail
    ... If you really don't want the SBS server to use SMTP outbound then just ... enter a block for SMTP with the servers IP address in your firewall ... understand that this is what SBS does and it's the proper way for any ... Calling an illegal alien an "undocumented worker" is like calling a ...
    (microsoft.public.windows.server.sbs)

Loading