Page 3 of 3 <123
Topic Options
#168411 - 2006-09-28 03:28 PM Re: Delete Registry Keys
Witto Offline
MM club member
*****

Registered: 2004-09-29
Posts: 1828
Loc: Belgium
K. I see.
Maybe other arg. The Firewall helps blocking computer viruses and worms from reaching your computer. I know viruses should not be on your trusted network, but you never know.

Top
#168412 - 2006-09-28 06:56 PM Re: Delete Registry Keys
Lonkero Administrator Offline
KiX Master Guru
*****

Registered: 2001-06-05
Posts: 22346
Loc: OK
lol.
that's what the av stuff is for.

Top
#168413 - 2006-09-28 06:57 PM Re: Delete Registry Keys
wrender Offline
Fresh Scripter

Registered: 2006-09-25
Posts: 22
On our network we normally keep file and print sharing off, and turn it on with group policy when needed. I think it takes a maximum of 120 min with replication and all that jazz before it takes affect.

I do agree, leaving the firewall on with file and print sharing blocked probably decreases the spread of a lot of viruses.

Top
#168414 - 2006-09-29 12:02 AM Re: Delete Registry Keys
Witto Offline
MM club member
*****

Registered: 2004-09-29
Posts: 1828
Loc: Belgium
I think File and Print sharing should not be blocked in your trusted networks. Otherwise you cannot remote admin the computers. The trusted networks can be defined in the rule that allows File and Print sharing. In fact, everything should be blocked except the things you need (think about ports for AV, remote assistance, remote desktop, tftp server,...).
Maybe AV stuff can help to clean your computer from viruses and worms, but a firewall can help to avoid that one of these things ever enter the computer.
Why bet on one horse if you've got two?

Top
#168415 - 2006-09-29 12:14 AM Re: Delete Registry Keys
Lonkero Administrator Offline
KiX Master Guru
*****

Registered: 2001-06-05
Posts: 22346
Loc: OK
lol.
if you allow lan traffic through those ports, it's same as if they didn't have the firewall on at all.
a) in lan environment, the attack comes from the neighbor machine. the one you opened the hole for
b) those ports and services are the ones todays viruses use to attack you

so, it's totally useless to use firewall in domain network. imho.

Top
#168416 - 2006-09-29 01:27 AM Re: Delete Registry Keys
therob Offline
Starting to like KiXtart

Registered: 2005-05-19
Posts: 150
Loc: Frankfurt/M., Germany
Quote:


so, it's totally useless to use firewall in domain network. imho.





Plus, in any but very small networks its nearly impossible to administrate.

I just had a conversation with a friend of mine who works as an admin in a small to middle sized company (500+ clients). They thought about implementing firewalls for every client. After a week of research they realized that in order to lock down the workstations as much as needed to get a better security, whithout hampering all the special apps running on the pc's, they would have at least 50 or 60 different firewall configurations. They dropped the whole thing.

Imho, if you have a tight security on your servers, good local antivirus, no vital data stored on local workstations and a proper firewall/antivirus for all incoming, local FW's would just increase complexity, not security.
_________________________
Eternity is a long time, especially towards the end. - W.Allan

Top
#168417 - 2006-09-29 01:46 AM Re: Delete Registry Keys
therob Offline
Starting to like KiXtart

Registered: 2005-05-19
Posts: 150
Loc: Frankfurt/M., Germany
Quote:


Maybe AV stuff can help to clean your computer from viruses and worms, but a firewall can help to avoid that one of these things ever enter the computer.





Most viruses in company networks spread via mail or infected documents. You dont catch them via local firewalls. Also, there have been lots of cases in the recent past where spyware or viruses simply disarmed software firewalls.

Quote:


Why bet on one horse if you've got two?





Because it just increases expenses for administration and suppport without increasing the security significantly.
_________________________
Eternity is a long time, especially towards the end. - W.Allan

Top
#168418 - 2006-09-29 02:58 AM Re: Delete Registry Keys
Howard Bullock Offline
KiX Supporter
*****

Registered: 2000-09-15
Posts: 5809
Loc: Harrisburg, PA USA
A firewall is a small part of protecting a computer in a corporate environemnt. The firewall is most useful on travling computers that get exposed to foreign networks. IPS and AV is where corporate computers are protected.
_________________________
Home page: http://www.kixhelp.com/hb/

Top
#168419 - 2006-09-29 03:04 AM Re: Delete Registry Keys
Gargoyle Offline
MM club member
*****

Registered: 2004-03-09
Posts: 1597
Loc: Valley of the Sun (Arizona, US...
Or there is real protection... Cisco Security Agent. Firewall / AV / Application watching / NAC all rolled into one..
Top
#168420 - 2006-09-29 07:25 AM Re: Delete Registry Keys
Lonkero Administrator Offline
KiX Master Guru
*****

Registered: 2001-06-05
Posts: 22346
Loc: OK
oh, this became suddenly a ad channel
Top
#168421 - 2006-09-29 04:43 PM Re: Delete Registry Keys
Gargoyle Offline
MM club member
*****

Registered: 2004-03-09
Posts: 1597
Loc: Valley of the Sun (Arizona, US...
Ok a bit of an ad, maybe I should have used "Hosted Intrusion Prevention System", but then again being a Cisco Geek..
Top
#168422 - 2006-09-29 06:22 PM Re: Delete Registry Keys
wrender Offline
Fresh Scripter

Registered: 2006-09-25
Posts: 22
WHat the hell are you guys talkin about? A firewall isn't useless inside a domain. I'm running over 150 windows xp clients, and about 100 windows 2000 clients. All 150 XP workstations are running a firewall, sure it adds a bit of processing overhead, but we haven't had any problems with compatibility between applications and server connections.
Also, you can adjust the windows Xp firewall in a flinch via group policy... I guess if you aren't running an active directory domain, it could be a pain.
If someone is going to attempt at hacking your network, it's most likely going to come from the disgruntled employees on the inside anyways. Not having a firewall on the workstations themselves is only going to make it easier for them.

Top
#168423 - 2006-09-29 06:48 PM Re: Delete Registry Keys
Witto Offline
MM club member
*****

Registered: 2004-09-29
Posts: 1828
Loc: Belgium
Thanks,
I just gave up.

Top
#168424 - 2006-09-29 06:50 PM Re: Delete Registry Keys
therob Offline
Starting to like KiXtart

Registered: 2005-05-19
Posts: 150
Loc: Frankfurt/M., Germany
Hey, if you guys think wearing gloves when having sex prevents you a little bit more from getting aids, thats fine with me.

Edited by therob (2006-09-29 06:54 PM)

Top
#168425 - 2006-09-29 07:19 PM Re: Delete Registry Keys
Witto Offline
MM club member
*****

Registered: 2004-09-29
Posts: 1828
Loc: Belgium
http://www.microsoft.com/windowsxp/using/security/learnmore/atkin_firewall.mspx#EYF
Top
#168426 - 2006-09-29 07:26 PM Re: Delete Registry Keys
NTDOC Administrator Offline
Administrator
*****

Registered: 2000-07-28
Posts: 11624
Loc: CA
(not directed specifically to you Witto)

Okay this is way off topic now. If everyone wants to post further on this subject please go to the General forum.

This has nothing to do with KiXtart.

The Starters forum is designed to assist new users in how to use KiXtart now how to convince someone to see things your way for general networking.

Top
#168427 - 2006-09-29 07:28 PM Re: Delete Registry Keys
Witto Offline
MM club member
*****

Registered: 2004-09-29
Posts: 1828
Loc: Belgium
This cannot be compared with sex. In the Windows Firewall, holes are deliberately made. You will not make holes in your preservative when having (unsafe) sex.
[Edit]
Whoops doc, had not seen your post yet. Sorry
[/Edit]


Edited by Witto (2006-09-29 07:30 PM)

Top
Page 3 of 3 <123


Moderator:  Jochen, Allen, Radimus, Glenn Barnas, ShaneEP, Ruud van Velsen, Arend_, Mart 
Hop to:
Shout Box

Who's Online
1 registered (Allen) and 363 anonymous users online.
Newest Members
SERoyalty, mytar, Gabriel, Alex_Evos, Dansen
17869 Registered Users

Generated in 0.205 seconds in which 0.143 seconds were spent on a total of 13 queries. Zlib compression enabled.

Search the board with:
superb Board Search
or try with google:
Google
Web kixtart.org