• We’re currently investigating an issue related to the forum theme and styling that is impacting page layout and visual formatting. The problem has been identified, and we are actively working on a resolution. There is no impact to user data or functionality, this is strictly a front-end display issue. We’ll post an update once the fix has been deployed. Thanks for your patience while we get this sorted.

Firewall Management

Armitage

Banned
Ok, so my company is standing up a website for a customer. The server is in a managed hosting facility.
We have a system here in our office that has to do somesome backend processing on data for the site. We manage the site from here on a pair of Linux boxen via ssl, and data is regularly posted from here to the site db over an ssl tunnel. Beyond that the computer here just needs to receive email, send email, and work with an outside FTP site.

Now for reasons that are to convoluted & bizarre to even go into here, this system needs to come off the corporate network. The bandwidth requirements are pretty modest, so we are planning to get a simple DSL line to keep on keeping on. Of course, we need a firewall on this.

Here's the rub. Corporate comm won't let us get the DSL line unless we have a firewall managed by our IT organization on it. But our IT organization is claiming that they don't have the manpower to support this. That it's going to take several hours a day every day to protect this connection, configuring, reviewing logs, etc..

I really want to raise the BS flag on this, but don't know enough about network security to do it. I'm thinking we put a decent hardware firewall on the line. Configure it once ... lock down everything incoming except email. And actually, that can be locked down to about 4 IPs. Maybe open up an incoming SSL connection to a few IPs. Set up an ipsec firewall on the linux boxen as well, turn off everything we don't need, keep up2date up to date, and we're good.

Am I hopelessly naive about network security, or are our IT guys just trying to play us for more manpower?
 
Originally posted by: Armitage

Am I hopelessly naive about network security, or are our IT guys just trying to play us for more manpower?

They are pulling your leg, a couple hours a day of manpower, every day, for 1 firewall? No way.
 
I could see how it could take a couple hours every day if your company has very strict security policies and if they log everything and require analysis of it. Sometimes I spend a couple hours a day with logs from one firewall when I'm tracking a suspicious activity.
 
Originally posted by: Boscoh
I could see how it could take a couple hours every day if your company has very strict security policies and if they log everything and require analysis of it. Sometimes I spend a couple hours a day with logs from one firewall when I'm tracking a suspicious activity.

Exactly. It all depends. It depends on how the security group is setup and to what detail the security policy dictates.

Although I have a hard time believing a single firewall would cause much of a fuss.

Demand that a security policy is enforced and then say "but it can't be because of resource contraints?"

Doesn't sound like you have a problem, but the security group does.
 
Originally posted by: spidey07
Originally posted by: Boscoh
I could see how it could take a couple hours every day if your company has very strict security policies and if they log everything and require analysis of it. Sometimes I spend a couple hours a day with logs from one firewall when I'm tracking a suspicious activity.

Exactly. It all depends. It depends on how the security group is setup and to what detail the security policy dictates.

Although I have a hard time believing a single firewall would cause much of a fuss.

Especially for as locked down as this will be from the get-go.

Demand that a security policy is enforced and then say "but it can't be because of resource contraints?"

Yea well, unfunded mandates are nothing new around here :roll:

Doesn't sound like you have a problem, but the security group does.

Thanks guys
 
they are pulling your leg about this you are right to think any good hardware firewall will do esp with port blocking and tracking.
perhaps they dont want to hassle with it or perhaps corp is just making it hard to accomplish?
good luck
jerome
 
Back
Top