Educause Security Discussion mailing list archives

Re: host based firewall for windows 2003 server?


From: "Lucas, Bryan" <b.lucas () TCU EDU>
Date: Fri, 14 Jul 2006 19:12:01 -0500

If its abandon-ware, I take that to mean it won't get any updates.  What
if a vulnerability is discovered?

Agree about SCW.

-----Original Message-----
From: Vuong Phung [mailto:vphung () SCIENCE SJSU EDU] 
Sent: Friday, July 14, 2006 5:56 PM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: Re: [SECURITY] host based firewall for windows 2003 server?

Thanks all for your response to my query. After much of testing both
commercial and freeware, I decided to use Sygate Personal Firewall 5.6
(abandon-ware, Symantec bought Sygate)  Just google it for a copy.

This software is easy to use, work right out of the box, has not given
me any trouble so far, alert me via email on port scan attempt, and the
Advanced Rules feature is awesome which allows me to block/allow in/out
traffic base on NIC (in case you have more than one NIC on your server),
hostname, mac address, subnet, applications, the ability to block/allow
traffic on schedule (yes, you tell it when to apply the rule), and
lastly - anti application hijacking. What it lacks is the ability to
forward logs to syslog.

Microsoft Security Configuration Wizard is a nightmare because it's easy
to apply but so many times HARD/FAIL to rollback. I personally recommend
this abandon-ware host firewall as an alternative to Windows 2003 server
built-in firewall.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Vuong Phung
Operating Systems Administrator
College of Science - Dean's Office

San Jose State University
One Washington Square
San Jose, CA 95192-0099
Duncan Hall 33

Tel 1.408.924.5056
Fax 1.408.924.5033
Web https://ncs.science.sjsu.edu/helpdesk
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

-----Original Message-----
From: Vuong Phung 
Sent: Thursday, June 15, 2006 9:36 AM
To: 'The EDUCAUSE Security Discussion Group Listserv'
Subject: host based firewall for windows 2003 server?


Windows 2003 built-in firewall only blocks incoming traffic and don't do
much logging and alerting. We are looking for a firewall to install on
Windows 2003 server to control  and monitor its outgoing and incoming
traffic. A lot of googling didn't show many products, and none of them
really stand out or have much review about the products. 

Does anyone know or use any third-party firewall on Windows 2003 server
that can control, monitor and alerting (via email or log to the event
log) its outgoing and incoming traffic?

Thanks!

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Vuong Phung
Operating Systems Administrator
College of Science - Dean's Office

San Jose State University
One Washington Square
San Jose, CA 95192-0099
Duncan Hall 33

Tel 1.408.924.5056
Fax 1.408.924.5033
Web https://ncs.science.sjsu.edu/helpdesk
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Current thread: