Re: firewall for SBS Standard network
- From: Dana Epp <dana@xxxxxxxxxxx>
- Date: Mon, 24 Apr 2006 15:31:22 GMT
Personally I don't think the RRAS firewall is enough on SBS Standard. Although it functions as expected, you have no real log auditing capabilities to KNOW if something is going wrong. This is a significant weakness if you ask me. On top of that, it is very difficult to associate strong rule-based security policies on the firewall as its not as clean as ISA 2004. For the price difference, seriously consider upgrading to Premium. For the value you get, it will probably be cheaper than buying a hardware firewall. And you will get the bonus of also getting SQL server on top of ISA 2004.
If you feel you must get a hardware firewall, I would recommend the Sonicwall TZ170. We use that (with the enhanced OS) to support our two-factor authentication needs and it has been great. Whatever firewall you get, make sure it supports both ingress and egress filtering. In other words, that you can set security policies to block both incoming and outgoing connections to properly control access control to minimize the impact of potentially hostile intent by both trusted and untrusted users. Those $50-$99 Netgear and Linksys NAT routers just won't cut it. Forget about them.
YMMV of course. Good luck.
---
Regards,
Dana Epp [Security MVP]
http://silverstr.ufies.org/blog/
TBW wrote:
Is there any consensus as to whether or not the firewall functionality native to SBS 2003 Standard Edition (i.e., NAT plus RRAS) is sufficient? Some users and admin will be connecting to the network from the Internet.
Especially if it's thought to be a necessity, which firewall appliances work well with SBS (i.e., which ones allow one to take advantage of SBS's capability to configure hardware routers)?
Thanks!
TW
.
- Prev by Date: Re: Exchange 2003 stops sending and receiving external emails every night
- Next by Date: Need to rebuild my SBS 2003 Premium Server
- Previous by thread: Exchange 2003 stops sending and receiving external emails every night
- Next by thread: Re: firewall for SBS Standard network
- Index(es):
Relevant Pages
|