Help me with edge security

Joined
Oct 17, 2004
Messages
41
Greetings,

I work at a small finance company with 40 employees and we need to strengthen our edge security. Right now we have 2 physical web servers hosing 12 web sites between them. The servers are sitting on the inside network and are domain members. These web servers talk to other servers via shares and our MS SQL Server.

We also have multiple XP workstations being accessed via remote desktop.

All of this is sitting behind a single Cisco 2821 router doing 1 to 1 NAT to the web sites and above mentioned XP workstations. There are ACLs restricting the open ports on all of the connections. IE 'This outside address can only talk to this internal address and port."

What concerens me is our network is only as secure as the (weak) passwords on the XP desktops being accessed via remote desktop. Also, if our web sites were hacked then the attacker will be sitting on our inside network and may have access to privilaged accounts that are used by the web servers themselves.

Our users love to surf and managemnt does not want to filter or monitor the surfing because they don't want to come across as "big brother" to the employees. Eveyone in the company keeps Facebook, Myspace, and Pandora open 24/7. That being said we have to rebuild machines on a regular basis because of virus/malware invections.

I'm looking at several options and wanted to get your thoughts on them.

1. Keep the existing router and put a Cisco ASA 5010 behind it.

2. Kep the existing router and put in an Astaro or Untangle box behind it.

3. Throw away the 2821 and put an ASA 5010 on the perimeter with an Astaro or Untangle box behind it.

Notice I didn't mention anything about a DMZ for the web servers. Unfortunatly, this is not an option at the moment because it would require way to much recoding that we don't have the time or resources for right now.

What are your thoughts? What do you do in this kind of situation?

Best regards,
The Dude
 
I'm not an expert, however the ASA with an IPS module is pretty solid,

If you require more routing features on your internal network. You can keep the 2821 and us it to do your routing
 
Oh, I forgot to mention that I have an internal layer 3 switch stack doing all of my internal routing between networks.
 
Oh, I forgot to mention that I have an internal layer 3 switch stack doing all of my internal routing between networks.

You could use the 2821 for routing and take that load off your switch. Let the router do what its suppose to. Though you could just leave it on the switch, either way
 
If you have staff that get infected quickly...having Untangle protecting your network will certainly cut waaaay back on your malware infections. Astaro has a "pay for" UTM product for businesses which also has anti spyware and anti virus protection to help.
 
You could use the 2821 for routing and take that load off your switch. Let the router do what its suppose to. Though you could just leave it on the switch, either way
you will hit the pps limitations of a 2821 if you're using it as a router-on-a-stick for heavy LAN routing...not what it is designed for.
 
You pretty much got this figured out. Couple of comments:
- you need to keep your 2821 if you do (BGP) peering with your provider(s)
- you might wanna consider using VPN for RDC - this allows you to have stronger passwords when accessing from 'net, can even use OTP and such, can use ASA for this
- for servers seems like you'll need some kind of IPS/IDS (maybe ASA module?) but you really should understand that it'll never be as secure as good ol' closed ports (read DMZ)
- definitely get mail/web gateway, might wanna consider IronPort as well if you're Cisco shop (but it's not cheap)
 
A couple of things i would do.

1. Increase password complexity: change every 90 days, history=5, lockout =3 attempts, minimum days=1, complexity=enabled.
2. Add Untangle Box.
3. OpenDNS, helps block a lot of malware, and can even be used for basic web filtering.
4. On the 2821 block all ports, then open ports on an as needed basis. Malware and hackers like to use obscure ports but if everything is disabled except for what is needed and is controlled through ACLs it will help prevent data leakage from malware that makes it onto your network, and make it much more difficult for an attacker to access your network.

Also you didnt mention but how are users remotely connecting to these XP workstations? Are you opening ports for each user, and changing the RDP port on the local machine or using TS Gateway?
 
RE: X.SCI
Fortunatly, we don't need it for BGP peering so getting rid of it is definatly an option.

A VPN solution is most definatly going to happen. I don't want these goofballs to have full network connectivity because God knows what's on their home machine. I'll probably do a VPN with it locked down to just RDP connections or a clientless SSL VPN solution. I like the one on the Cisco ASA but WOW are the SSL VPN licenses expensive.

I agree about the IPS/IDS module and I'm evaluating that. I really, really want to move the outward facing stuff into a DMZ but until our web sites are recoded to behave there's nothing I can do.

I'll look into IronPort.


RE: Nitrobass24
Yep, increase password complexity and such. I tried that the first month I was there and it went over badly. Very badly. I got nothing but complaints then the company owner told me to put it back because it was just to inconvient. ***SIGH***

I'm looking at Untangle and Astaro for a UTM services. Right now I'm leaning toward Astaro. I much prefer its virus engine, Avira, and it seems to be geared more toward a business environment. Untangle is by far easier to configure though.

I'll into using Open DNS.

On the 2821 we do block all inbound ports except service specific stuff. I agree with blocking outbound ports. Do you have any suggestions as to how to determine what needs to be blocked vs. left open?

Remote connections? Each user connects to a unique outside address that has a one to one NAT to their inside fixed IP. ACL rules limit the traffic to only to port 3389 - the default RDP port. 12 users that do this so we have 12 outside addresses, 12 fixed inside addresses and all the appropriate ACLs to make it happen.
 
For the passwords, what are they now? and what did you try to go to? Maybe something *Bad* should happen to his account, then he will straighten up.

I would look at documentation for your critical applications to see what/if any outbound ports it needs.
Then i would setup a sniffing tool to see what kind of traffic is leaving and track down items that have the heaviest use.
Then just turn it all off and wait for complaints, prob more than half of them will be people complaining because XXXXXX application doesnt work and i cant goof off at work any longer :(
 
Back
Top