Re: Proxy Server versus Firewall

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



When you say 'We currently have a firewall enabled.' it can mean several
things.

Do you have a firewall appliance? and if so, is this a 'simple NAT router'
(which isn't really a firewall at all) or a more advance appliance?
Do you mean that you have a two NIC SBS Standard setup and chose to 'enable
firewall' during the CEICW? This is not much better than a simple NAT
router, using basic windows RRAS packet filtering capability.
Or, do you mean you have a two NIC SBS Premium with ISA installed? ISA is a
fully certified packet & application filtering firewall and proxy server. It
has an advantage over many firewall products in the area of 'application
layer' filtering (and no , I don't mean port level filtering).

A properly configured proxy/firewall will inspect the requests and returned
traffic, controlling access based on 'who' makes the request, 'when' they
make the request, 'where' the request is sent, validity of the outgoing
request, and validity of the returned data. ISA, in conjunction with the ISA
firewall client will also validate 'which application' made the request.

"jsccorps" <jsccorps@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:40FEE173-15A5-47DB-BF3A-200B0EF7A7C8@xxxxxxxxxxxxxxxx
Client plans to do online banking (e.g., transferring scanned checks) .
We
currently have a firewall enabled. I was told that to enhance security an
"authenticating proxy server" should be installed. Looking for additional
insight in this area. Any suggested articles or web sites would be
appreciated.


.



Relevant Pages

  • Re: SSL-Tunnel blocked?
    ... My guess is that something is being attempted that the Web Proxy Service ... My suggestion is to install the Firewall Client on the Workstation. ... the net into Powerpoint, ISA blocks the request, the output is shown ... I am guessing that since ISA cannot look at the traffic inside ...
    (microsoft.public.isa)
  • Re: recommendation for internet usage tracking
    ... I've been pushing ISA appliances for some time now, where they fit the business need. ... On an executable level though, for a device or program to decide which executable is making the request, it must run an agent on the requesting machine that reports back. ... I've made this same argument about software firewalls that do 'outgoing' security as well. ... A firewall, whether at the network edge, or the PC's network-stack edge, should only be trusted to scan *inbound* security. ...
    (microsoft.public.windows.server.sbs)
  • Re: [Full-Disclosure] Re: Empirical data surrounding guards and firewalls.
    ... The firewall is not content filtering, thus does not stop bad requests ... connection to a webserver. ... carrying an illegal object (an illegally formed request). ...
    (Full-Disclosure)
  • Re: Excluding internal IPs from being proxied
    ... This log entry says that since I do not have firewall policy that allows web ... the request is denied. ... *correctly* treats the request as being destined to the internal network, ... The point is the request should *never* be processed by web proxy ...
    (microsoft.public.isa)
  • Help- Cant VPN with Cisco client from behind ISA and Pix back to back config.
    ... I have a back to back firewall design. ... first go through ISA and ISA is ... connected directly to a PIX firewall which goes to a Cisco router to ... in ISA and creating a protocol rule to accept any request. ...
    (microsoft.public.isa.vpn)