thedude0901
n00b
- Joined
- Oct 17, 2004
- Messages
- 41
Greetings,
I work at a small finance company with 40 employees and we need to strengthen our edge security. Right now we have 2 physical web servers hosing 12 web sites between them. The servers are sitting on the inside network and are domain members. These web servers talk to other servers via shares and our MS SQL Server.
We also have multiple XP workstations being accessed via remote desktop.
All of this is sitting behind a single Cisco 2821 router doing 1 to 1 NAT to the web sites and above mentioned XP workstations. There are ACLs restricting the open ports on all of the connections. IE 'This outside address can only talk to this internal address and port."
What concerens me is our network is only as secure as the (weak) passwords on the XP desktops being accessed via remote desktop. Also, if our web sites were hacked then the attacker will be sitting on our inside network and may have access to privilaged accounts that are used by the web servers themselves.
Our users love to surf and managemnt does not want to filter or monitor the surfing because they don't want to come across as "big brother" to the employees. Eveyone in the company keeps Facebook, Myspace, and Pandora open 24/7. That being said we have to rebuild machines on a regular basis because of virus/malware invections.
I'm looking at several options and wanted to get your thoughts on them.
1. Keep the existing router and put a Cisco ASA 5010 behind it.
2. Kep the existing router and put in an Astaro or Untangle box behind it.
3. Throw away the 2821 and put an ASA 5010 on the perimeter with an Astaro or Untangle box behind it.
Notice I didn't mention anything about a DMZ for the web servers. Unfortunatly, this is not an option at the moment because it would require way to much recoding that we don't have the time or resources for right now.
What are your thoughts? What do you do in this kind of situation?
Best regards,
The Dude
I work at a small finance company with 40 employees and we need to strengthen our edge security. Right now we have 2 physical web servers hosing 12 web sites between them. The servers are sitting on the inside network and are domain members. These web servers talk to other servers via shares and our MS SQL Server.
We also have multiple XP workstations being accessed via remote desktop.
All of this is sitting behind a single Cisco 2821 router doing 1 to 1 NAT to the web sites and above mentioned XP workstations. There are ACLs restricting the open ports on all of the connections. IE 'This outside address can only talk to this internal address and port."
What concerens me is our network is only as secure as the (weak) passwords on the XP desktops being accessed via remote desktop. Also, if our web sites were hacked then the attacker will be sitting on our inside network and may have access to privilaged accounts that are used by the web servers themselves.
Our users love to surf and managemnt does not want to filter or monitor the surfing because they don't want to come across as "big brother" to the employees. Eveyone in the company keeps Facebook, Myspace, and Pandora open 24/7. That being said we have to rebuild machines on a regular basis because of virus/malware invections.
I'm looking at several options and wanted to get your thoughts on them.
1. Keep the existing router and put a Cisco ASA 5010 behind it.
2. Kep the existing router and put in an Astaro or Untangle box behind it.
3. Throw away the 2821 and put an ASA 5010 on the perimeter with an Astaro or Untangle box behind it.
Notice I didn't mention anything about a DMZ for the web servers. Unfortunatly, this is not an option at the moment because it would require way to much recoding that we don't have the time or resources for right now.
What are your thoughts? What do you do in this kind of situation?
Best regards,
The Dude