Jump to content

Recommended Posts

Posted

I am looking at a number of options as an alternative to our Censornet problem. I am favouring a Microsoft solution but as I have not used it before I would like some advice/opinions on its setup, implemtation & use. Is it a proper OS or does it need Win2K3?

 

I will also need a web filtering piece of software. Any suggestions for a lowcost/ free solution to work with ISA would be gratefullty received.

Posted

Doing your own filtering is a nightmare, liability wise - does your LA provide a service you could buy into? Its one of those things that its nice to blame the LA for, if the kids start browsing porn, having your own box might get messy if you are filtering to a different standard than other schools in your LA.

 

If you still want ISA to use as a proxy, its pretty idiot proof to setup and configure, all wizard based. ISA is an application that installs as a service on Windows server.

Posted

We use ISA 2004 Standard + Server 2K3 here.

We have SmartFilter (http://www.securecomputing.com) and it has been the best and cheapest filtering we have come across so far. Simple to use and the new version (4.2) has some really nice features such as forcing safe-mode searches on google and yahoo.

It also comes bundled with logging software (web based) which is really nice and simple to use.

Posted
Our LA is encouraging schools to move away from getting Internet services from them .They want us to do our own Internet. At the moment we do our own filtering & Firewall with Censornet but it's proving unreliable. Thanks for the suggestions.
Posted
Were i work (CLC) we use websence, that provides filtering for roughly 30 schools. It seems to be very relable. Before that we were using Smartfilter & Bess
Posted

Lipjam: SmoothWall's "Guardian" solution is in the process of becoming BECTA accredited, and will be one of very few that are. I know there are a few of our customers lurking on here, and I am sure they will comment on our suitability or otherwise.

 

We'd happily provide you with an evaluation - either just the web filter, or firewall + whole package.

 

If you definitely want to go the ISA route you will have to add your own filtering, be that surfy, or smartfilter or whatever. ISA is considered a pretty poor firewall however, so I would caution against using it as your 1st skin if you take that route.

Posted

Thats my cue.

 

Tada :)

 

We have Smoothwall Corporate Guardian 5 and moving to 6 for our filtering solution and intend to opt out of the LEA's

 

It does exactly what it says on the tin and the smoothwall family are nice people to deal with.

 

Ben

Posted

Cheers plexer ;) we do try our best!

 

I'm interested to know where lipjam's LA that's *encouraging* this sort of thing is... first time I have heard of such a thing happening!n Usually they are a bit recalcitrant.

 

WRT responsibility - I know some peole say "oh i'd rather be able to blame the LA/RBC" but has anyone ever seen these people take the blame for an incident -- i'll bet the firey poker ends up in the local netman's eye, not some ivory tower RBC type :)

Posted

@tom_newton

 

ISA is considered a pretty poor firewall however, so I would caution against using it as your 1st skin if you take that route.

 

I don't agree with statement, its a far better firewall than some of the so called HW firewall/packet filters. Just because runs on top of a MS os and software based is not a good or for that matter a valid reason to call it poor.

 

I agree that one should have simple packet filter firewall at the first ring to cut own the real garbage and nasty stuff but for SPI etc and deep packet inspection its very good (isa server).

 

Tom can you provide few points on why you think isa is a poor firewall please I am curious to know becaue we have got it running here (ever since we moved away from our RBC two years ago now) and its been fine and have not had any problems, we are using at the perimeter.

 

Ashok.

Posted
@tom_newton

 

ISA is considered a pretty poor firewall however, so I would caution against using it as your 1st skin if you take that route.

 

I don't agree with statement, its a far better firewall than some of the so called HW firewall/packet filters. Just because runs on top of a MS os and software based is not a good or for that matter a valid reason to call it poor.

 

I agree that one should have simple packet filter firewall at the first ring to cut own the real garbage and nasty stuff but for SPI etc and deep packet inspection its very good (isa server).

 

Tom can you provide few points on why you think isa is a poor firewall please I am curious to know becaue we have got it running here (ever since we moved away from our RBC two years ago now) and its been fine and have not had any problems, we are using at the perimeter.

Was about to ask the same. Let it be heard ISA 2004 has NEVER had a remote hack yet as far as I have heard. No exploits, nothing....

Can other firewalls say that all the time?

It also provides extremely granular VPN access which is a breeze to setup.

Posted

It's not so much that the firewall is bad, it's more that its a general purpose server OS being used as a perimeter firewall.

 

When we use Linux, we take the kernel, make alterations, and then careflly chose the other tools we add.

 

When you use ISA, you're basically taking a stock server OS and trying to make it fit for purpose - not a great idea. As long as you're doing *something* outside of it, then i'd say yes, fine, use it for the stateful inspection/app layer stuff, but i'd never put it direct onto my router.

Posted
Our LA is encouraging schools to move away from getting Internet services from them .They want us to do our own Internet. At the moment we do our own filtering & Firewall with Censornet but it's proving unreliable. Thanks for the suggestions.

 

Which LA is this? Do they mean moving away from an RBC and buying your 'Net connection wholesale from someone like BT or NTL:Telewest Business?

Posted
It's not so much that the firewall is bad, it's more that its a general purpose server OS being used as a perimeter firewall.

 

When we use Linux, we take the kernel, make alterations, and then careflly chose the other tools we add.

 

When you use ISA, you're basically taking a stock server OS and trying to make it fit for purpose - not a great idea. As long as you're doing *something* outside of it, then i'd say yes, fine, use it for the stateful inspection/app layer stuff, but i'd never put it direct onto my router.

 

There is SCW wiazard that hardens the base OS by disabling the service and all you need to do is to select "ISA Server" and the Security Configuration wiaxrd will disable all services not required and keep the isa and thus hardening the server OS. This is the same sort of things that you guys do with you kernal modifications etc.

 

Ashok.

Posted
Ashok - I would suggest that hardening an operating system is more than merely disabling services. Personally, I wouldn't be happy running an ISA system, but a good many people are; having said that, many people use PPTP as well. I guess I am just a bit of a hard guy to please, but then that's my job ;)
Posted

Tom

I did have a mess about with Smoothwall but couldn't configure it as we have two subnets and Censornet accomodates the two gateways. I may be wrong but I don't think smoothwall can do the same? I have little knowledge of Linux that is why I favour the Microsoft solution. It is looking expensive though so I would be happy for any help advice you can offer.

 

I am waiting for a layer 3 managed switch to arrive so will not need two gateways. I want the new solution up and running before term starts in Sept so have a bit of time to play around and try out various solutions.

Posted
I've got a smoothwall here as well. It's the business. Smoothwall has an easy to use webfrontend to set it up so no 'linux knowledge' is required -it just works.
Posted

lipjam: It depends which version of SmoothWall you're looking at, and what you're trying to do ;) We have instalations from companies with 10 10 man offices, to 10,000 users all going through a central location - and all points in between :)

 

Give me a ring and we can go through what you're trying to do - might give you some ideas anyway! (phone no. in sig block)

Posted

Got SmoothWall here (SchoolGuardian) and so far it's been fantastic..

We did try to use ISA a long time ago an a Galaxy far far....

 

Damn I knew i shouldn't have watched all them star wars films last night 8O

Posted
Ashok - I would suggest that hardening an operating system is more than merely disabling services. Personally, I wouldn't be happy running an ISA system, but a good many people are; having said that, many people use PPTP as well. I guess I am just a bit of a hard guy to please, but then that's my job ;)

 

Hi Tom,

 

When i mentioned about the services being disabled, that is one aspect of it, there are other things it modified and therefore disables the other functionality of windows server say. This is done through selecting the role(s) of the server and depending on which role you select it configuring the back-end os for that role and nothing else.

 

Your solutions may be easier may be better or worse but certainly commenting that isa is poor at perimeter or second ring is bad. I guess people decide on ease of use, deployment and administration and some may find it easier to configuring firewalls using web browser etc and some like to have proper front-end gui.

 

There are also other people making comments about it being expensive, its not that expensive for schools i.e. £50 approx for the base server license, and £150 approx for the isa server itself so not too bad. Native MS AD support it good and if you're a microsoft shop then it makes it ideal.

 

I'm only carrying on this debate because so far i haven't seen any advisories regarding isa server 2004 or 2006 but have seen many issues regarding hardware firewalls even from big guys.

 

Agree with the PPTP bit some people are taking chances with this and should use something more secure i.e. L2TP/IPSec but that's the firewall admin being either lazy, or ignorant.

 

Ash.

Posted

Ash,

 

I never said ISA was poor as a second ring f/w, I just said I wouldn't trust it on the perimeter. It certainly is an inexpensive option for education. Lack of advisories is a BAD thing - no software is perfect, and if there are no advisories this is very suspicious, though I am sure that's not the case with ISA - it's just that the advisories are a touch oblique - you have to go looking for flaws in parts of ISA. http://secunia.com/advisories/26003/ for example, at a guess ISA is vulnerable to that, but it's not an "ISA vuln". TBH, there are rarely advisories against firewall code itself such as IPtables/netfilter or even microsoft's firewall.

 

In all probability you're better off with ISA than some of the low end stuff- supportability is worth more than most features :)

 

Tom

Posted
Lack of advisories is a BAD thing - no software is perfect, and if there are no advisories this is very suspicious, though I am sure that's not the case with ISA

The same thing could be said for Smoothwall could it not.

it's just that the advisories are a touch oblique - you have to go looking for flaws in parts of ISA. http://secunia.com/advisories/26003/ for example, at a guess ISA is vulnerable to that, but it's not an "ISA vuln". TBH, there are rarely advisories against firewall code itself such as IPtables/netfilter or even microsoft's firewall.

Considering by the looks of the MS site ISA does not require .Net 2.0 then its not a concern. Also requires logged on user which no one would ever allow. Its like allowing users to login using SSH to smoothwall when there is a ssh exploit. Its not a issue if you trust the person doing it.

 

Really I dont think this thread is about the security issues as none, as we have proved, exist for ISA 2004 so I really dont think its relevant to even imply it has holes and one is better then the other when such evidence is lacking. Open source can have as many issues regardless of how you pack it. Its up to the admin to secure it down properly and if he is doing his job both have minimal risk associated.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...