Firewall Placement Questions?

Dec 16, 2004 6 Replies

Gentlemen;



I have a client with all Netopia routers. One at the main office and one at each branch location. Each branch has a VPN from its own router to the main office router. Each branch is its own subnet but has access to the main office subnet at well. We've got Netopia's basic firewall filters enabled and we use NAT as well.



Another vendor has been pressuring my client to install a Cisco PIX firewall to provide better "protection" for their network. First thing is that this vendor want to dump the Netopia's and install ALL Cisco gear. When I took over this client they were having extreme problems with their existing Cisco 25xx routers and I replaced them with the Netopias and for a few years they have been and are still running extremely well.



So, my question(s) is:



Is there any way to install the PIX firewall INSIDE the LAN (on the NAT'ed side of the Netopia)? Honestly the client does NOT want to replace the existing VPN's because of their extreme reliabilty.



Any suggestions and/or recommendations appreciated.



Thanks,



Bob



It all depends on what they have to protect. Since the Netopia is a router and not a Firewall, while NAT is a good barrier in most cases, it's not a firewall.

If you have the ability to block ranges of ports outbound in the router (without impacting the VPN's) then you have close to what you would be doing in the firewall - if you can't block outbound access while still allowing the VPN's to function, then you might consider a firewall, but you don't have to go with CISCO, and as long as you disable NAT, any firewall will work just fine - you can enable NAT on the firewall, but doing a double NAT (router and firewall) is very problematic.

What issues is the client having with NAT?

What evidence (I mean evidence, not sales brochures!) does he give that the PIX will give better protection?

Never touch a running system.

Wolfgang

NONE !!!

My recommendation EXACTLY!

No issues what-so-ever!

A third party "security auditor" (an employee from a CPA firm) was looking at the logs of ONE of their servers that is NAT'ed to a public address to allow access from the outside from SPECIFIC IP's (wrappers). The syslog had several entries that IP xx.xx.xx.xx was attempting to port scan on certain ports. However, they were NOT allowed access. Guess that's what intrusion protection is all about.

The CEO thinks that because of the auditor's statement WE must be doing something wrong.

Hope this adds fuel to the kindling fire.

Bob

I think this is the third time I've seen someone mention an audit by a CPA firm and I'm amazed that they can get away with it. CPA firms don't exactly have shining security reputations, are known for billing clients when not actually providing anything, and are a lot like lawyers :)

I've yet to see an audit done my a CPA firm that did anything except generate more billable hours for the firm.

Leythos ( snipped-for-privacy@nowhere.lan) wrote: : In article , : snipped-for-privacy@financialdatacorp.com says... : > A third party "security auditor" (an employee from a CPA firm) was : > looking at the logs of ONE of their servers

: I think this is the third time I've seen someone mention an audit by a : CPA firm and I'm amazed that they can get away with it. CPA firms don't : exactly have shining security reputations, are known for billing clients : when not actually providing anything, and are a lot like lawyers :)

: I've yet to see an audit done my a CPA firm that did anything except : generate more billable hours for the firm.

It depends

Most public corporations have to have an annual external audit [as do non-profits]. Most of the large audit companies now also do audits of the IT systems used by the company.

If you go into this process with eyes open, the audit can be a very useful 2nd set of eyes on potential security risks. However, having been on the receiving side of this for over 20 years, you have to be aware that many of these auditors work off of a checklist based on 'best practices' which tend to be based on what their large corporate customers do. Be prepared to argue certain points if the 'best practice' does not apply to your organization.

[A good example is the collision between 'best practice' for a database system is found to not be running and the audit finding wants it done. The problem is that the database in question is part of a larger ERP application. The response we gave was that we would query the ERP vendor to see if there were any issues in following the recommendation and, if not, schedule the modification as part of the change control process]

Always have a meeting with the IS audit team prior to the start of work to go over the scope of work and the type of tests they will do. Work out the roadmap for the audit before it starts.

After it is completed, schedule meetings with the auditors to go over any findings and discus mitigation and/or objections to the findings with them. You also need to make your financial people aware of any issues and have a firm understanding that you will not blindly follow an auditor's recommendation just because it is a recommendation.

I agree and have been part of many audits, but I'm not an accountant :)

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required