From: Jason Joines <joines@bus.okstate.edu>
To: netfilter@lists.netfilter.org
Subject: Re: OT: iptables-like firewall for windows?
Date: Tue, 26 Aug 2003 11:55:43 -0500 [thread overview]
Message-ID: <3F4B910F.40600@bus.okstate.edu> (raw)
In-Reply-To: <Pine.LNX.4.53.0308222103330.3988@xena.cft.ca.us>
Jim Carter wrote:
>On Fri, 22 Aug 2003, Jason Joines wrote:
>
>
>
>> We have a completely Linux back-end environment but unfortunately
>>hundreds of windows desktops. I'm pretty tired of all the attacks on
>>the unprotected windows boxes but don't have the authority to put up a
>>network firewall. We protect all of our Linux servers with iptables.
>>Does anyone know of a similar tool for windows, particularly w2k? The
>>built-in stuff seems to be virtually worthless.
>>
>>
>
>The native filter in WinXP can be configured to totally block or totally
>open selected ports. Unfortunately you have to open 135 etc. if you expect
>to have outsiders mount your filesystems or (I think) if you want to mount
>theirs. Not much help there. 3rd party products might be more flexible.
>
>I think you have a social engineering problem. Has your department
>chairman or dean or whatever gotten hit by MSBlaster, SoBig, etc? Explain
>to him/her that a virus could ruin his whole day. Here at UCLA several
>other departments were essentially shut down because they had no firewall.
>My department has a very effective one, plus a pretty aggressive policy on
>patches, and we evaded MSBlaster, but due to the lack of internal barriers
>and some machines that were missed, SoBig got us yesterday. The campus
>telecom service has taken the "unprecedented" step of blocking relevant
>ports at the campus perimeter, to protect our less clueful departments from
>the worms and to protect the outside world from our less clueful
>departments. Tell that to your chairman.
>
>James F. Carter (postmaster) Voice 310 825 2897 FAX 310 206 6673
>UCLA-Mathnet; 6115 MSA; 405 Hilgard Ave.; Los Angeles, CA, USA 90095-1555
>Email: jimc@math.ucla.edu http://www.math.ucla.edu/~jimc (q.v. for PGP key)
>
>
You're exactly right, it's a social/political problem. My direct
supervisor, the college IT manager and his direct supervisor, the dean
of the college, are 100% on board. We have asked for permission to put
up our own firewall to protect the network many times and been denied.
We have asked for the university network operations group to put up
whatever they like, NAT us, etc., etc., and been denied may times. The
campus was hit with thousands of infections and when we asked to have
routing of port 135 completely disabled in and out of our network and
disabled on the switches, they couldn't believe we wanted that and had
to have it in writing first.
We had many machines hit but were fortunate enough to be able to clean
and patch them via network boot (PXE - Rembo Tool Kit -
http://www.rembo.com). Many of the other colleges had no such tool and
are having to manually rebuild machines. We have a new CIO over the
university system who seems to worship microshaft. His security
philosophy seems to be "microsoft can release patches faster than
hackers can come up with new attacks and viruses". We have lots of
unusual applications that often get broken by microshaft patches and
like to do thorough testing before deploying them.
Maybe a few more attacks wacking thousands of machines will change
their policies.
Jason
===========
next prev parent reply other threads:[~2003-08-26 16:55 UTC|newest]
Thread overview: 18+ messages / expand[flat|nested] mbox.gz Atom feed top
2003-08-22 13:26 OT: iptables-like firewall for windows? Jason Joines
2003-08-22 19:51 ` Tony Clayton
2003-08-22 21:06 ` Shawn
2003-08-22 23:33 ` Arnt Karlsen
2003-08-23 0:06 ` Shawn
2003-08-25 15:30 ` Jason Joines
2003-08-25 20:33 ` Arnt Karlsen
2003-08-23 1:22 ` Mark E. Donaldson
2003-08-26 16:25 ` Jason Joines
2003-08-26 16:57 ` Jason Joines
2003-08-23 1:46 ` OT: " cc
2003-08-23 3:54 ` Matt Hellman
2003-08-23 4:14 ` Jim Carter
2003-08-26 16:55 ` Jason Joines [this message]
2003-08-26 16:58 ` Jason Joines
2003-09-01 5:33 ` Michael
2003-08-25 9:29 ` Maciej Soltysiak
-- strict thread matches above, loose matches on Subject: below --
2003-09-04 10:42 Luke Hinds
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=3F4B910F.40600@bus.okstate.edu \
--to=joines@bus.okstate.edu \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox