Security Basics mailing list archives

RE: Win IPTables?


From: Bénoni MARTIN <Benoni.MARTIN () libertis ga>
Date: Wed, 28 Apr 2004 09:09:36 +0100

As I have been told that twice, I will reply to the list. When a possible intruder will try to break in our network, he 
will have to bypass a router (with some filtering) and a PIX (maybe an ISA as well), so it should be OK. I was just 
thinking about adding another layer of security on the web server itself, in the case of a bypass of the other 
filtering devices...and to protect it from the inside! :)


-----Message d'origine-----
De : Data Security - F. Millotti [mailto:francesco.millotti () datasecurity it] 
Envoyé : mercredi 28 avril 2004 08:46
À : Bénoni MARTIN
Objet : R: Win IPTables?

Hi Martin,
My humble opinion is: do no do it this way, place a "real" FW in front
of it, possibly a box with a different OS.

Cheers, 
Francesco



-----Messaggio originale-----
Da: Bénoni MARTIN [mailto:Benoni.MARTIN () libertis ga] 
Inviato: martedì 27 aprile 2004 16.35
A: security-basics () securityfocus com
Oggetto: Win IPTables?


Hi community,

I have been trying to find out if there was an equivalent of iptables
under a Windows box.

I have an Windows 2003 box, with an IIS and an SQL Server 2000 running
on it (I know it would be better to set that up on two different
machines, but well... :) ), and I was wondering how to secure it with a
personal FW.

Any idea will be welcomed!

Cheers!


------------------------------------------------------------------------
---
Ethical Hacking at the InfoSec Institute. Mention this ad and get $545
off 
any course! All of our class sizes are guaranteed to be 10 students or
less 
to facilitate one-on-one interaction with one of our expert instructors.

Attend a course taught by an expert instructor with years of
in-the-field 
pen testing experience in our state of the art hacking lab. Master the
skills 
of an Ethical Hacker to better assess the security of your organization.

Visit us at: 
http://www.infosecinstitute.com/courses/ethical_hacking_training.html
------------------------------------------------------------------------
----




---------------------------------------------------------------------------
Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off
any course! All of our class sizes are guaranteed to be 10 students or less
to facilitate one-on-one interaction with one of our expert instructors.
Attend a course taught by an expert instructor with years of in-the-field
pen testing experience in our state of the art hacking lab. Master the skills
of an Ethical Hacker to better assess the security of your organization.
Visit us at:
http://www.infosecinstitute.com/courses/ethical_hacking_training.html
----------------------------------------------------------------------------


Current thread: