X-No-Archive: Yes
"Moe Trin" wrote in message news: snipped-for-privacy@compton.phx.az.us...
Well, the anti-virus software I have, Avast, protects all the machines behind it as well. Anything coming into or out of the gateway machine is scanned for viruses, and if it detects a virus, the entire network is halted, until I log onto the gateway machine and acknowledge. In short, when a virus is detected, all network communications are halted. Avast is very good at protecting my network from viruses, maybe too good. For some reason, it thinks that PrecisionTime, from Gator, is a trojan, and Avast will sometimes halt the entire network, because it sees what it thinks was a virus. The only freeware version of WebWassher acts as a proxy, web filter, and popup blocker all in one. If you can still find the old freeware version out there, it is quite good. It also does not leave the gaping security hole that CyBlock did when I tried it. WebWasher can be configured so that only the machines in your subnet can access the proxy. Cyblock has no such security. I discovered this about a year ago, when I started seeing strange addresses in the logs. When I removed CyBlock, I no longer had the security hole. Wavecrest needs to do something about the security hole in their product, if they ever want to compete in the Web filtering business. If you choose CyBlock as your filtering solution, and use the software version, you MUST have a software firewall on the same machine, to restrict both incoming and outgoing traffic on CyBlock, restricting incoming traffic to your subnet, and outgoing traffic to ports 80 and 443. The kind of security restrictions that you need, if you are going to use CyBlock, without a gaping security hole in your system cannot be done with a hardware appliance. A hardware appliance would not be able to restrict incoming access to your subnet, or restrict outgoing traffic to ports 80 and 443. LIke I said elsehwhere, I am surprised that I never heard from Comcast when that security hole was there, becuase ALL ISPs, whether they be DSL, dial-up, cable, or whatever, frown upon open relays on their networks, because of the fact that the spammers take advantage of those. If you are going to have a gateway machine, A minumum of 512MB is a must. Also, turn off ICS, and use a third-party product, such as AllegroSurrf (it is a LOT more secure than Windows ICS).
CSU Sacramento, but they were working on a curriculum change, at the time, so things have likely changed, but back in 1999, we were taught everything you ever wantted to know about Windows networking. Like I say, they were working on a curriculum change at the time, so things have likely changed since then, but that is what was taught in 1999.