Jump to content

Recommended Posts

Posted
I keep it disabled with a GPO. It should be worth noting however that the XP Firewall is only 50%, blocking incoming but not outgoing connections. So long as your security is up-to-date and you have something secure/reliable at the edge of your network you should be absolutely fine.
Posted
ours is off by gpo on every machine, we have our isa server between us and the internet, and even then on the other side of our isa we have a cisco router provided by the lea which is also a firewall.
Posted
would having the firewall on or off have any affect on a fully patched network if the likes of confiker got through a usb?

 

That is the only reason why i have it enabled, is because of the above... we do have updated anti-virus but it's better to be safe then sorry :) and it dont do any harm with it been turned on

Posted

Disable it as anti-virus realise on your firewall being off to update if you use a enterprise console and any exam software that you run.

 

Cheers Rich

Posted

Antivirus *should* catch viruses . . . . .

Perimeter security *should* keep you safe from attack from outside . . . . .

 

But all technology has off days. Zero day exploits exist, AV software does not catch all viruses, and not all attacks come from outside. If you get a worm inside the network and there's not security between machines, then you're stuffed.

 

One other important thing to think about is that not all PCs stay on site - laptops will get taken home, plugged into home networks and in some cases directly into the Internet. And what's the first thing numpty ISP tech support tells the home user to do? Disable their firewalls & antivirus software . . . .

 

So I set up like this: all machines have the firewall on, via group policy, and can't be turned off by the user. When connected to the domain, exceptions are there for WMI, Remote Desktop and the odd one or two that require file/print sharing (or something more exotic). When not connected, there are no exceptions allowed.

Posted (edited)
I keep it disabled with a GPO. It should be worth noting however that the XP Firewall is only 50%, blocking incoming but not outgoing connections. So long as your security is up-to-date and you have something secure/reliable at the edge of your network you should be absolutely fine.

 

 

Defence in depth. Why disable and easy to configure built in security feature? Yes it only covers incoming traffic but that's the most important in my opinion. We turn it on via GPO and then set exceptions.

Perimeter firewalls don't protect against USB drives or laptops bought on site, firewalls are the best defence against zero day exploits. Anti-Virus software is the 'last' line of defence.

Edited by cookie_monster

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...