Networks Thread, Server firewalls inside the perimeter in Technical; in another thread, RoyG suggested that it would be OK to give students admin rights so long as server security ...
-
8th July 2006, 12:30 PM #1
- Rep Power
- 14
Server firewalls inside the perimeter
in another thread, RoyG suggested that it would be OK to give students admin rights so long as server security was up to par. Best practice normally calls for uptodate patching and disabling unused services.
I was just wondering if, added to the above, people here also have a firewall inside the LAN between their servers and client PCs
-
-
IDG Tech News
-
11th July 2006, 11:20 PM #2
- Rep Power
- 14
Re: Server firewalls inside the perimeter
-
-
12th July 2006, 04:08 AM #3 Re: Server firewalls inside the perimeter

Originally Posted by
ITWombat in another thread, RoyG suggested that it would be OK to give students admin rights so long as server security was up to par. Best practice normally calls for uptodate patching and disabling unused services.
I was just wondering if, added to the above, people here also have a firewall inside the LAN between their servers and client PCs
No no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no. It's just plain bad.
-
-
12th July 2006, 07:43 AM #4 Re: Server firewalls inside the perimeter
We don't have it here, but it was common practise in a couple of places I contracted in. Development servers were firewalled off from the rest of the LAN, so was the finance server.
If it's _well_ documented and done for sensible reasons, it can work. Problems arise when changes aren't documented. If you're doing it because a server isn't patched / secure you still have issues, but certain patches break certain expensive systems (I'm looking at you Oracle) so firewalling is sometimes the only option..
IIRC (few years ago), employees at Sophos (that have been there long enough to be considered sensible), have two computers on their desk, one for the Internet and one for the internal lan. They fire people who attempt to move files from one to another.
-
-
12th July 2006, 09:23 AM #5 Re: Server firewalls inside the perimeter
in another thread, RoyG suggested that it would be OK to give students admin rights so long as server security was up to par
I didn't get the impression he was talking about production machines - any computer can be a server if it serves something and I don't see any problem giving kids admin on 'servers' so they can learn it . Some schools let kids bring in their own laptops, some schools even buy laptops for kids - there is no difference. I can't prevent a student brining in an AD DC on his/her laptop and probably it should be encouraged
Its definately not a good idea to give anyone admin rights to production servers except admins.
-
-
12th July 2006, 09:33 AM #6
- Rep Power
- 0
Re: Server firewalls inside the perimeter

Originally Posted by
Dos_Box No no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no no. It's just plain bad.
ROFL
Actually, I saw that thread too. I think the admin rights were for PCs not servers (now that would be scary). Roy also used hardware disk reset as additonal measure against pishing and persistent badness.
The question really is whether there would much gained. A lot of malware uses common ports for SMB, SSL, SMTP etc (remember Blaster)
-
SHARE:
Similar Threads
-
By db260179 in forum Network and Classroom Management
Replies: 7
Last Post: 25th July 2007, 07:07 PM
-
By GrumbleDook in forum Blue Skies
Replies: 2
Last Post: 21st July 2007, 12:40 PM
-
By BigBadVinny in forum Networks
Replies: 5
Last Post: 15th June 2007, 08:53 AM
-
By ITWombat in forum General Chat
Replies: 18
Last Post: 5th March 2007, 02:10 PM
-
By ITWombat in forum Comments and Suggestions
Replies: 4
Last Post: 16th October 2006, 08:34 AM
Thread Information
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules