Re: Best practices: Two nic's but have harware firewall
- From: "SuperGumby [SBS MVP]" <not@xxxxxxxxxxx>
- Date: Tue, 28 Feb 2006 23:30:24 +1100
You're talking about 'Protocol Layer' filtering. Yes, I'm well aware of
WatchGuard facilities along these lines. WatchGuard both proxy and filter at
the 'Protocol Layer'.
ISA does 'Application Layer' filtering, though one process may be allowed to
make connections to a remote service (let's say port 25, SMTP) another
process will be blocked from doing so. (There is a common problem where JAVA
apps do not pass currently logged on user credentials to ISA, which blocks
the HTTP traffic. It is easily remedied but lowers ISA security)
If your 'device' cannot distinguish between processes it is inferior to ISA
in combination with the ISA client. Some firewall devices also support a
'client application' which allows 'Application Layer' filtering, such
devices, and the licensing of them, normally cost more than ISA,
particularly ISA on SBS.
C'mon Leythos. You've been around long enough and must recognise me. Don't
point me to someone's base site URL. I'm pretty much insulted you thought it
worthwhile.
"Leythos" <void@xxxxxxxxxxx> wrote in message
news:dnWMf.138435$Q11.59796@xxxxxxxxxxxxxxxxxxxxxxxxx
In article <uCPuAFCPGHA.740@xxxxxxxxxxxxxxxxxxxx>, not@xxxxxxxxxxx
says...
I am not aware of any application layer filtering in WatchGuard products.
This may be a failing on my part. I would welcome a link to any
references
to such.
They provide SMTP and HTTP Proxy services built into it - they also
allow user enumeration with Windows. They have the ability to filter
content out of sessions while still allowing the approved content...
You can read more about them at www.watchguard.com - don't look at the
low end units, start with the X-700 and higher.
--
spam999free@xxxxxxxxxx
remove 999 in order to email me
.
- References:
- Best practices: Two nic's but have harware firewall
- From: Child
- Re: Best practices: Two nic's but have harware firewall
- From: SuperGumby [SBS MVP]
- Re: Best practices: Two nic's but have harware firewall
- From: Child
- Re: Best practices: Two nic's but have harware firewall
- From: SuperGumby [SBS MVP]
- Re: Best practices: Two nic's but have harware firewall
- From: Child
- Re: Best practices: Two nic's but have harware firewall
- From: SuperGumby [SBS MVP]
- Re: Best practices: Two nic's but have harware firewall
- From: SuperGumby [SBS MVP]
- Best practices: Two nic's but have harware firewall
- Prev by Date: RE: disconnecting from server
- Next by Date: VPN sometimes works and sometimes not - Error 691
- Previous by thread: Re: Best practices: Two nic's but have harware firewall
- Next by thread: Re: Best practices: Two nic's but have harware firewall
- Index(es):
Relevant Pages
|