Off-topic Talk Where overpaid, underworked S2000 owners waste the worst part of their days before the drive home. This forum is for general chit chat and discussions not covered by the other off-topic forums.

Hardware Firewall Question

Thread Tools
 
Old Jul 11, 2004 | 11:41 AM
  #1  
mingster's Avatar
Thread Starter
Registered User
20 Year Member
 
Joined: Oct 2000
Posts: 10,134
Likes: 0
From: Baltimore
Default Hardware Firewall Question

My company's IP address is now black listed by CBL and Spamhaus

I checked and realized some fool on our network had an infected computer. How would a hardware firewall prevent these spamming viruses? Or there is no such thing?
Reply
Old Jul 11, 2004 | 12:09 PM
  #2  
steve c's Avatar
Registered User
 
Joined: Jun 2001
Posts: 6,792
Likes: 4
Default

It depends.

The simple answer is yes and no.

A firewall will "hide" your internal network from external queries -- so the script kiddies who scan IP blocks won't find any vulnerable machines. This is of course supposing you set up the firewall correctly and don't do anything stupid.

On the other hand, your machines can still become infected if a stupid user executes something bad, aka a trojan.

The best approach is to tier your protection. Start with a firewall, a Cisco Pix 515 etc (or even a cheapy Linksys SOHO 80 dollar job), and add some manner of virus scanning to your inbound email system. If you use sendmail or qmail there are a lot of nice free options out there, if you use Exchange you can buy a few decent packages.

Follow up with a virus scanner on each computer within your network to stop anyone from bringing stuff in from the outside on memory sticks, CD's, Zips etc.

I get scanned on average 4 times an hour -- and recently watched as a fresh 2003 server machine was up for less than 4 hours outside of the firewall before being owned.

If you want help or more detail hit me up via PM, I will be glad to talk you through what I would do in your shoes.
Reply
Old Jul 11, 2004 | 12:43 PM
  #3  
cashout's Avatar
Registered User
 
Joined: Feb 2003
Posts: 4,472
Likes: 0
From: Sydney
Default


From what I know about spamhouse, a firewall will not help you any.

Spamhouse blacklists IP addresses and that means that is your mail server that is blacklisted.

The only way I know is to have your mail server do header matching (matches the from bit to an internal emal address) on outgoing email. This will stop the spam a lot as most of the spamming viruses use random email addresses on the from address.
Reply
Old Jul 11, 2004 | 04:04 PM
  #4  
flitcroft's Avatar
Registered User
20 Year Member
 
Joined: Sep 2003
Posts: 3,802
Likes: 0
From: Los Angeles
Default

Originally Posted by mingster,Jul 11 2004, 11:41 AM
How would a hardware firewall prevent these spamming viruses? Or there is no such thing?
Very easily. You just block outgoin port 25 from all client machines. The only machine that needs to send outgoing email is your mail server. If the infected hosts are blocked at the firewall they won't be able to spam.
Reply
Old Jul 13, 2004 | 04:46 PM
  #5  
Voodoo_S2K's Avatar
 
Joined: Aug 2001
Posts: 17,792
Likes: 4
From: Bay Area, California
Default

Originally Posted by flitcroft,Jul 11 2004, 04:04 PM
Very easily. You just block outgoin port 25 from all client machines. The only machine that needs to send outgoing email is your mail server. If the infected hosts are blocked at the firewall they won't be able to spam.
This is exactly what we do for all our clients. Only allow outbound port 25 traffic on the mail server and set up alerts to notify if it detects port 25 traffic on any other machine.
Reply
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
VTEC_Junkie
Off-topic Talk
5
Mar 11, 2004 07:48 AM
VTEC_Junkie
Off-topic Talk
22
Jan 29, 2004 09:58 AM
s2ksleepy
Off-topic Talk
14
Jan 24, 2004 03:55 PM
-S2K-2K-
Off-topic Talk
6
Dec 8, 2003 04:28 AM




All times are GMT -8. The time now is 09:57 PM.