ass17
Members-
Posts
2,201 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by ass17
-
I think long term offsite servers (which might still use a virtual environment) will happen, but short term, there are so many people going physical --> virtual --> cloud as a natural progression route, that there is a market for VM. But I do agree that you will still need an internal infrastructure, so good networking knowledge is and will be essential. But then again how In depth does your knowledge need to be if everything is offsite, thus nothing to protect or serve apart from Internet.
-
But not everyone can, you'll learn switching as part of VMware along with direct I/O, vcenter management etc....
-
I think your all missing the point, what you should be thinking about is what is happening to the world of IT, then if you come to the same conclusion as me then you should be looking at doing s course in VMware or other server virtualisation. Then look at Microsoft server technologies that would sit on the VM. I would not necessarily do a Cisco course unless you wish to specialise in Cisco. I did complete my CCNA a few years ago but to be honest there are a lot of videos on YouTube/Lynda to do with networking and after watching them you could skip any networking course and just take the exam saving you a load of cash. It's my opinion and not necessarily the right answer for you but hopefully I have given you something to think about [emoji106]🏻
-
https://blog.night-shade.org.uk/2014/01/smoothwall-in-a-heterogeneous-network/ if it's still relevant
-
Not tried it but good answer! [emoji106]🏻
-
Client software only, you could try deploystudio to push it out, but I'm pretty sure you still have to manually configure it once installed, it's years since I've used it but all the info should be on Google.
-
Try looking into ident or Kerberos, if you insist on NTLM then you could use authoxy
-
We use it on all PCs in school, sits as a hidden service, with connection password and specific connection port. It installs updates on shutdown VB script.
-
IP helpers reside on the VLAN interface where the VLAN IP is set, which are all on our core switches, had no issues and no IP helpers at the edge were required.
-
to DMZ or not to DMZ, that is the question?
ass17 replied to ass17's topic in Internet Related/Filtering/Firewall
Ok I see, so if we reverse proxy servers that have web access that will protect that side of things. But what can I do if we allow external RDP access (port forwarded, IPS turned on for this rule) to a terminal server that needs access to mail, sims, etc... Can anything be done? -
to DMZ or not to DMZ, that is the question?
ass17 replied to ass17's topic in Internet Related/Filtering/Firewall
What I'm struggling to understand is how sticking a reverse proxy in will stop a hacker from gaining access to servers? Or by having a reverse proxy they hit the firewall/reverse proxy it goes and gets the data on behalf of the hacker therefore they never get beyond the firewall? If this is the case will a reverse proxy only deal with HTTP/HTTPS requests or is it literally any type of request made? IMAP/SMTP for example -
to DMZ or not to DMZ, that is the question?
ass17 replied to ass17's topic in Internet Related/Filtering/Firewall
My next question would be do I need an additional reverse proxy if smoothwall is a firewall, IPS, reverse proxy all in one job, can that become effectively my DMZ? @TomNewton -
to DMZ or not to DMZ, that is the question?
ass17 replied to ass17's topic in Internet Related/Filtering/Firewall
I only said TMG because we have it sitting there as a backup transparent proxy just in case smoothwall won't allow certain access to government sites that our accounts team have to submit data to. But certainly it is something we could virtualise if we decided to use a different reverse proxy -
to DMZ or not to DMZ, that is the question?
ass17 replied to ass17's topic in Internet Related/Filtering/Firewall
I think instead of trying to put servers in to different DMZ's, I'm now thinking the answer to turn the TMG into a reverse proxy. That way you'll have: Internet --> smoothwall --> TMG Reverse Proxy --> internal servers If I have it the right way around and in my DMZ is a simply the reverse proxy. Does anyone else use this approach? -
to DMZ or not to DMZ, that is the question?
ass17 replied to ass17's topic in Internet Related/Filtering/Firewall
You speak a lot of sense, I'm going to use this for future projects [emoji1] -
to DMZ or not to DMZ, that is the question?
ass17 replied to ass17's topic in Internet Related/Filtering/Firewall
Our smoothwall box controls access to each of the six virtual interfaces that each wifi network is on, so rules are in place to allow specific communication across networks, so I suppose it's kind of a DMZ for each network. We do also have a TMG firewall also which is setup with basic rules but mainly acts as a second proxy for users that need access out to government websites, that for some reason smoothwall won't allow because of our rule setup. So your advice is to use TMG as a second level firewall? I'll check with my network manager to see how they work specifically and how they are wired, I suspect as it stands TMG goes through smoothwall transparently but I could be wrong. -
to DMZ or not to DMZ, that is the question?
ass17 replied to ass17's topic in Internet Related/Filtering/Firewall
Two firewalls, please can you explain your thinking behind this, I interested to know. As it stands we will use our smoothwall as our firewall, it is kind of the heartbeat of our network, internal and wifi. Could we in essence DMZ none critical data servers that are accessible to external and create individual DMZ's per each server that has critical data on it? -
to DMZ or not to DMZ, that is the question?
ass17 replied to ass17's topic in Internet Related/Filtering/Firewall
In what way, can you explain your thinking, thanks -
to DMZ or not to DMZ, that is the question?
ass17 replied to ass17's topic in Internet Related/Filtering/Firewall
Our sims server is exposed to external access through very specific ports, for the teacher app to function. But I wouldn't want to put sims in a dmz with the mail and web server. The biggest problem is that a lot of personal data is now being exposed to the outside world, like sims, work folders feature etc So what do you do? Yes mail and web can go DMZ but what about sims or staff data server hosting work folders etc... -
to DMZ or not to DMZ, that is the question?
ass17 replied to ass17's topic in Internet Related/Filtering/Firewall
Come on guys constructive please :-) Will an IPS really stop everything? I mean by having a DMZ you are limiting what a hacker is exposed to if they compromise the domain admin account or such like... -
Hi, We are re-assessing our security on our network and was wondering if people still DMZ mail, web servers etc? Like most, we wish to limit specific servers, in terms of external user access, from attacks. So allow mail server to contact DC, DNS etc but nothing else like user data. So to my question I assume the cheapest is to create a DMZ on smoothwall and put specific servers in their. or is there a better way, and functioanliy/security outways the costs? For example is Citris NetScaler an option? I would love some advice please what other have done to secure services available to external users... Thanks
