IanT Posted November 26, 2009 Posted November 26, 2009 Do you keep the Windows Firewall enabled or disabled on your machines at your school?
EduTech Posted November 26, 2009 Posted November 26, 2009 Enabled Exceptions in place if need to be. File and Print Sharing Turned ON James.
Michael Posted November 26, 2009 Posted November 26, 2009 I keep it disabled with a GPO. It should be worth noting however that the XP Firewall is only 50%, blocking incoming but not outgoing connections. So long as your security is up-to-date and you have something secure/reliable at the edge of your network you should be absolutely fine.
RabbieBurns Posted November 26, 2009 Posted November 26, 2009 would having the firewall on or off have any affect on a fully patched network if the likes of confiker got through a usb?
Michael Posted November 26, 2009 Posted November 26, 2009 Every school should be running anti-virus software, so if it's any good, it should catch out such viruses.
glennda Posted November 26, 2009 Posted November 26, 2009 ours is off by gpo on every machine, we have our isa server between us and the internet, and even then on the other side of our isa we have a cisco router provided by the lea which is also a firewall.
RabbieBurns Posted November 26, 2009 Posted November 26, 2009 Every school should be running anti-virus software, so if it's any good, it should catch out such viruses. true but a load of folk on here had it there was loads of posts
EduTech Posted November 26, 2009 Posted November 26, 2009 would having the firewall on or off have any affect on a fully patched network if the likes of confiker got through a usb? That is the only reason why i have it enabled, is because of the above... we do have updated anti-virus but it's better to be safe then sorry and it dont do any harm with it been turned on
Rick2134 Posted November 26, 2009 Posted November 26, 2009 Disable it as anti-virus realise on your firewall being off to update if you use a enterprise console and any exam software that you run. Cheers Rich
rh91uk Posted November 29, 2009 Posted November 29, 2009 We did keep it disabled but due to our recent outbreak of conficker we turned it back on, adding exceptions in GPO for WMI and VNC
theriver Posted November 29, 2009 Posted November 29, 2009 Antivirus *should* catch viruses . . . . . Perimeter security *should* keep you safe from attack from outside . . . . . But all technology has off days. Zero day exploits exist, AV software does not catch all viruses, and not all attacks come from outside. If you get a worm inside the network and there's not security between machines, then you're stuffed. One other important thing to think about is that not all PCs stay on site - laptops will get taken home, plugged into home networks and in some cases directly into the Internet. And what's the first thing numpty ISP tech support tells the home user to do? Disable their firewalls & antivirus software . . . . So I set up like this: all machines have the firewall on, via group policy, and can't be turned off by the user. When connected to the domain, exceptions are there for WMI, Remote Desktop and the odd one or two that require file/print sharing (or something more exotic). When not connected, there are no exceptions allowed.
Simcfc73 Posted November 29, 2009 Posted November 29, 2009 Defo on, it takes 10 minutes to GPO it and get the exceptions sorted and it may not be perfect but even it it gives me 1% extra protection its worth it.
cookie_monster Posted November 29, 2009 Posted November 29, 2009 (edited) I keep it disabled with a GPO. It should be worth noting however that the XP Firewall is only 50%, blocking incoming but not outgoing connections. So long as your security is up-to-date and you have something secure/reliable at the edge of your network you should be absolutely fine. Defence in depth. Why disable and easy to configure built in security feature? Yes it only covers incoming traffic but that's the most important in my opinion. We turn it on via GPO and then set exceptions. Perimeter firewalls don't protect against USB drives or laptops bought on site, firewalls are the best defence against zero day exploits. Anti-Virus software is the 'last' line of defence. Edited November 29, 2009 by cookie_monster
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now