Jump to content

Recommended Posts

Posted

Hi everyone,

 

I've been asking a few questions here recently, and about to ask another!

 

Background is that I work with a small local IT support company and we've recently taken over a small business (5 employees). Their servers are running Server 2008 Standard (3x Servers).

They have 1 domain controller with just AD, DHCP and DNS installed, the second is the "admin" server i.e home drives, sophos and printers etc go there along with terminal services (remoteapp). Last is a web host which hosts the "/tsweb" page and acts as the gateway and broker for the session connections.

 

Currently, on their firewall they have port 443 and 3391 open which goes to the TS Gateway. The firewall is Sophos UTM and they have all networks allowed, apart from Korea, China and a few others (13 in total I think). My main concern is that this server isn't in the DMZ, however they get virtually no traffic and it only goes to the login page which required AD auth so how big of an issue is it leaving it out of the DMZ? The servers are virtual and Sophos runs inside of a VM on an HP DL380 G5. Their backups go to a NAS which is in another part of the office. I want to get this offsite eventually however works well for them currently.

 

The AD side of things is done very well currently, with no scheduled tasks going via "Administrator" and about 25 security groups. I'm just after some general advice on how to protect the network better.

 

They are looking to expand their main office and have some members of the public coming in whilst sitting in reception. They have UniFi for wireless and standard layer 2 switches with 2 vlans on (2 and 3) - 2 is the main network vlan and 3 is one that was going to be for the guest wireless but never configured.

 

If you could give me some advice with going forward in regards to the overall setup that'd be great. We are going to upgrade to Server 2016 eventually however would like to get security sorted first. Anything applicable to small business security tips please post below!

 

Thank you.

 

Whistler

Posted
Please don't take this the wrong way but your asking us what is the best way forward that's like me saying her are the keys to my Kingdom but make one mistake and it will all come crashing down giving advice is one thing but asking for how to do something is another (thats the way I read it anyway don't know about anyone else ) do you know what a dmz is used for?
Posted
Please don't take this the wrong way but your asking us what is the best way forward that's like me saying her are the keys to my Kingdom but make one mistake and it will all come crashing down giving advice is one thing but asking for how to do something is another (thats the way I read it anyway don't know about anyone else ) do you know what a dmz is used for?

 

Hi Kevin,

 

I somewhat understand your thinking. I'm asking for opinions on how to move forward with this and what other people would do. Additionally, I'm interested as to how other people would do it, quite so given both the context and content of my question.

 

I'm new to the industry so have little experience. I do know what a DMZ is used for, hence me asking if it'd be worth putting the Web Host onto it to separate it from the main network from a security standpoint. I've read it's not essential but I was asking from a security perspective from people who on here would know a lot more than me.

 

Again, I'm asking for people's opinions which would encompass as to how other people would do it.

 

 

Whistler.

Posted
first thing i would advise is not to make any config changes - not until you have have had either some sort of training or being watched by a senior consultant who has gone over your plan on improvements. that you would think make an improvement on things - as a starting point if i was you i would look what kit they have - document everything - and get a feeling for the business first - look at how they do things and research on what could A) improve business as a whole by implementation of such service B) reduce cost of IT expenditure within the business )these are just examples but given that they are a small company im guessing they don't have cust out going cost - however i maybe wrong you would know more than me obvs - do you have a general plan of what you would like to achieve

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...