Blocking Access to web-based email

Aug 11, 2005 26 Replies

I hate to tell you this, but I could setup a Proxy server on one of the Linux boxes and tell then setup a firewall rule to all it outbound while content filtering users that don't use the proxy.

Keep trying - the only thing a firewall appliance isn't good for is controlling what applications run on your nodes, and since no one expects a firewall appliance to control applications on workstations/servers, it's really a mute point.

Maybe you need to take a couple security and network design classes.

The alternative Charles proposes is a toy firewall on every node (that each user can bypass at will, though he doesn't seem to believe it) gives the illusion of more safety. That's more important to him.

Hey, hey!!! He's already taken one microsoft approved networking class, so what more could he possibly need. Something like RFC1180 perhaps?

Old guy

I had gathered that his experience is very limited and almost gave up on him.

X-No-Archive: Yes

The firewall is only installed on the gateway machine, and all the other machines behind it are firewalled. As I have said before, the gateway machine currently runs:

AllegroSurf - DHCP, NAT and Socks Proxy Tiny Personal Firewall - Network firewall WebWasher - Filtering HTTP proxy ProxyPro - restricted access proxy for full access SpamBam - Spam filtering Avast - Anti-Virus protection NewsProxy - Usenet proxy and filter

We had that in college at CSU Sacramento as a requirement when I went there in the late 1990s. All business school students were requireed to take this class. You learned everything you would ever need or want to know about Microsoft Networking. We were taught to everything using software. I dont know about today, but they did not teach hardware firewall appliances, just software-based solutions. Hardware appliances lack the flexibility of a software-based solution running on a gateway machine. Plus, CyBlock, SurfControl, WebWasher, and other software-based content filtering solutions can do a lot more than anything in a hardware firewall. That is why the companies that make these solutions have made a lot of money, even in the implosion in the tech industry. They are much better at content filtering then anyhthing you can do with any kind of firewall solution, software or hardware. These companies do all the grunt-work for you and send an update a few times week.

Charles - you really have to get over this "learned everything" as you didn't learn much based on what I've read from you.

I hate to say this, but you've not learned anything about Networking or about Security, and seem to know less than many people that come here their first time.

You need to start LISTENING TO US. If you would listen you might actually learn a few things about security.

I've already provided you with information on how Firewall Appliances can do everything you've mentioned. The only function that the firewall appliances wont do, that I know of, is filtering content from Usenet sessions.

And you statement "They are much better at content filtering then anything you can do with any kind of firewall solution, software or hardware." just shows your complete lack of understanding and how you must really want to remain ignorant of solutions that other use - and that we've told you work and provide those functions.

[list of toy proxy applications snipped]

Charles - it was suggested a while ago to try using a packet sniffer like Ethereal. I realize this is not part of windoze, but neither is that bunch of toy proxies you are using. Your security is built on an extremely fragile base - which you'd see by looking at those packets.

which we showed you was based on inaccurate information, because microsoft doesn't know how IP networking works - they only started

13 years after everyone else. They tried to use the same concepts they developed for their original proprietary (and broken) attempt at small office networking (more than six years after Novell, Xerox, Banyon, Apple, IBM... actually there's a rather extensive list), but the only thing that scaled with NETBEUI were the massive security holes, which was OK as far as I was concerned, because NETBEUI couldn't even use a router - never mind connect to ANY other network. Microsoft's idea of reaching off-network was to dial into a BBS using "terminal". But then, terminals existed in other software back in the 1960s, and UUCP from early 1977 did more than windoze terminal ever could - again, only 10 years earlier.

So, you admit that you know nothing about hardware (big surprise) because "they didn't teach that" - I guess you also didn't learn how to do research and learn from other sources. (Admittedly, the popular magazines don't do anything except to regurgitating advertising crap from vendors. You _could_ read some books, but I guess that seems to be a reach for you.) And because you weren't taught anything in that one class, you never learned why and how they work.

But you just said that you don't know anything about appliances, so how can you make comparisons.

Have you been to

formatting link
and ordered your UNIX clone software yet? You can have your choice of hundreds of versions of Linux - they even have BSD. After all, that microsoft version of UNIX is on the horizon, and given your learning speed, you are wasting precious time by waiting.

Old guy

With a Fortigate, it's a simple matter to create a different protection profile, for example for admins, and maybe a third one for testing, and maybe a 4th one for public/boardroom/wireless access. Then apply these to the various access policies -- some of which are authenticated either through local username/pw combos or through an external service such as radius or ldap, and some of which are not. You can bind MACs to IP's too.

Then there is only one gateway, no proxy setup at all on the workstation.

It can filter IM by examining the packets, so it can't be fooled by falling back to port 80. These protocols are addressed in the Intrusion Prevention System.

IM by using SMB's or similar can be blocked by policy or by IPS.

It can filter web-based mail services using the category filter (websense-ish).

If you submit new links (based on your observation of your logs) via the web page, to Fortinet, that users have found for web-based mail services, they will add it within a day or two and every other Fortigate in the world will immediately also block it if they have webmail blocking enabled.

I've found their response to false positives on several occasions to be less than a day, and when they make the change, again every unit in the world is changed immediately (or as soon as their locally configured cache expires).

One box, no moving parts, $1000 for a unit with a year of all subscriptions (AV, IPS, SPAM filter, Web filter), has Internal, DMZ, WAN1, WAN2 interfaces, VPN.

Why play with toys?

formatting link

-Russ.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required