Jump to content

Recommended Posts

Posted
Lack of advisories is a BAD thing - no software is perfect, and if there are no advisories this is very suspicious, though I am sure that's not the case with ISA

 

The same thing could be said for Smoothwall could it not.

 

That depends - if by the same thing you mean "The vulnerabilities are larglely a sum of the vulnerable parts", then yes, if you mean "no advisories" - we don't (often) directly issue advisories unless we feel there would be a distinct benefit for our customers, we usually rely on the advisories for the relevant component. Patch management is, of course, handled centrally, so it's not down to the customer to handle updates for discrete parts.

 

it's just that the advisories are a touch oblique - you have to go looking for flaws in parts of ISA. http://secunia.com/advisories/26003/ for example, at a guess ISA is vulnerable to that, but it's not an "ISA vuln". TBH, there are rarely advisories against firewall code itself such as IPtables/netfilter or even microsoft's firewall.

Considering by the looks of the MS site ISA does not require .Net 2.0 then its not a concern. Also requires logged on user which no one would ever allow. Its like allowing users to login using SSH to smoothwall when there is a ssh exploit. Its not a issue if you trust the person doing it.

That was just the last "general MS advisory" I had lying about :) My point being that (like ourselves) ISa is a "sum of parts" and as such won't have (m)any "specific" vulns.

Really I dont think this thread is about the security issues as none, as we have proved, exist for ISA 2004 so I really dont think its relevant to even

Hang on! We haven't "proved" any such thing, and to say something has no holes is incredibly dangerous. I am sure I couldn't find a single security company who would stand up and swear there's no holes in their product - no-one can ever be 100% sure - unless they're talking about a "hello world"!

 

imply it has holes and one is better then the other when such evidence is lacking. Open source can have as many issues regardless of how you pack it. Its up to the admin to secure it down properly and if he is doing his job both have minimal risk associated.

 

I did not (intend to) imply that anything was "better" or "worse", simply that ISA would be far from my first choice at the perimeter. That said, I would rather have ANY firewall with a competant admin than any without. If we are honest, the human component is 90% of the security.

 

Right... lets see if I have got the quoting correct here... I have the distinct feeling its going to be squiffy... [click!]

Posted
Hang on! We haven't "proved" any such thing, and to say something has no holes is incredibly dangerous. I am sure I couldn't find a single security company who would stand up and swear there's no holes in their product - no-one can ever be 100% sure - unless they're talking about a "hello world"!

Sorry my phrasing was bad, I meant "proved there are no *known* ISA exploits (remote)". The MS advisory as you say was a example ;)

Lets call personal preference like you say, as to which firewall you like. Both have good and bad points and there own issues associated but both are firewalls that do a good job. At least no one has blackice (well the older versions were BAD) :D

Posted
I meant "proved there are no *known* ISA exploits (remote)".

 

You should of researched this assertion, I bothered to pull up the CVE entries for ISA 2004.

 

http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-7027

http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-3652

http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-1651

 

At least no one has blackice (well the older versions were BAD)

 

No, they were fine. BlackIce was an IDS not a firewall.

Posted

I really dont want this thread going down this route but I want to stick up for poor ISA so here we go.

1:

http://www.securityfocus.com/archive/1/archive/1/433350/30/5100/threaded

Suggests its actually to do with the log files in CSV format and that 3rd party apps are the problem and its not really ISA's fault. By default though I think ISA uses a local MSDE to store the logs so unless you were CSV'ing your logs AND your 3rd party viewer had a problem with the < in the logs, would you have a issue.

This is what the guy posting the response says (in brief):

I don't think it should be one application's responsibility to protect

against all the possible attacks that could be launched against

third-party products that happen to parse the original application's

output - unless either the application's core functionality is to

protect against such an attack (e.g. an anti-virus product that sits

between the Internet and a desktop machine).

 

2:

It states on the page:

NOTE: as of 20060715, this could not be reproduced by third parties.

Also see:

http://www.securityfocus.com/archive/1/archive/1/440247/100/0/threaded

so it may not be valid at all (not got time to test).

 

3:

Disputed - "Neither ISA Server 2004 nor Windows 2003 Basic Firewall support IPv6 filtering ... This is different network protocol."

Its a BAD admin that enables IPv6 routing on the ISA. I know that you need to "know" these issues but that's why MS invented the hardening tool for ISA.

See http://www.emailbattles.com/2006/04/28/broadband_aadfaggbbb_gd/ for more on the debate and options.

Yes ISA should support IPv6 but it doesn't. This is a negative point for it but if you dont enable/use it then really its a moot point. MS have a thing on there site saying how to remove it. See:

http://www.microsoft.com/technet/isa/2004/plan/unsupportedconfigs.mspx#Protocol and scroll down.

 

Think all that info seems correct :)

Posted
your arguing that IPV6/ISA is only secure if you don't use it???? WTF?
I am saying that ISA server is a secure IPv4 firewall. It does not support IPv6 filtering as it states on MS, so unless you need specific IPv6 filtering (note: it will still pass through but thats the concern in point) then ISA 2004 is perfect for the job. Just dont allow/install it on the gateway.

As of right now I cant think of a real reason that you need external IPv6 traffic, nothing requires it that our school needs as far as I have found.

If/When IPv6 is a standard you can get the upgrade for ISA and buy support then for it.

If you can tell me of a true *need* for allow IPv6 out of your network on to the internet, and supporting it internally to allow this, please tell me as it may be something we have not considered. But right now our network users have no need of IPv6 filtering/access. If in the future we do I will simply upgrade ISA.

 

This thread seems rather OT now as ISA security was not really the question in the original post.

Posted

Only thing I can think of related to IPv6 is that some OS's have it enabled by default (Mac OS X, Vista, Linux). So given the chance, they will talk IPv6 to anyone that asks.

 

I imagine things could end in tears if your relying on your firewall to block IPv6 and it's oblivious.

Posted

IPv6 will probably be supported in future service packs for isa server 2004/2006.

 

I agree that at present there is no need for it considering IPv4 had NAT, QoS and few other tweaks that can be made one can really take ample time to upgrade to IPv6.

 

I know all the JANET, UKERNA etc are using the combination of IPv6 and IPv4. There is a hotfix or patch/update for windows xp and 2000 that allows the use of IPv6.

 

I like to pop the question regarding ipv6. How many firewalls either first ring or second actually processes IPv6 traffic in the world specific? not many i think so the fact that isa server supports ipv6 or not is not really that important.

 

Ash.

Posted

In theory, a well designed firewall should follow a 'default deny' principle. If it understands IPv6, it should block it. If it doesn't understand IPv6, it should still block it (under a blanket 'unknown protocols' block).

 

Mine behaves as above, how about everyone else's? We've already established what ISA 2k4 does, yuck!

Posted
In theory, a well designed firewall should follow a 'default deny' principle. If it understands IPv6, it should block it. If it doesn't understand IPv6, it should still block it (under a blanket 'unknown protocols' block).

 

Mine behaves as above, how about everyone else's? We've already established what ISA 2k4 does, yuck!

 

Begs the question again!! who is actually using IPv6? if people are really desperate to run IPv6 (I can't think of any at the mo.) then install additional tool to block IPV6 and ipv6 supports authentication and its own security anyway (network layer security) so i don't really see how this is going to cause any problems. I don't see many people rushing to join the IPv6 revolution.

 

Geoff are you slagging off the isa server because its from MS, smell like that to me here, get the penguins out your heads once in a while.

 

Ash.

Posted

I've no idea who uses IPv6. I know m6bone exists. On a more practical note, I think 4to6 (or vice versa) is a more likely usage.

 

My main point was, IPv6 is here. Devices use it, and some things have it enabled by default. Thus you need to deal with it, if you like it or not.

 

ZeroHour pointed out that ISA ignored it, I pointed out that this was silly and can lead to tears. If ZeroHour was wrong stating this fact, please let the both of us know.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...