Computer Support Uk

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Monday, 28 September 2009

Three top firewall tuning tips

Posted on 02:30 by Unknown

Every firewall is different and has different capabilities, but let's take a look at three common areas that don't get any attention when you're in a hurry -- but which can improve your security and security awareness.

  1. MONITOR AND BLOCK OUTBOUND NETWORK TRAFFIC
    Most companies operate on a fairly relaxed basis, with a security policy that follows the "nothing gets in but anyone can go out" model. When you're getting started, this is the fast path to success. Once you're set, though, it's time to revisit this policy. In large enterprises, all outbound traffic is strictly controlled, and typically forced through a proxy server of some sort to provide content filtering and threat mitigation (such as antivirus scanning). You may not need that in a midmarket network, but you probably are letting more traffic out than you should.

    The easiest example is outbound SMTP (email traffic). In a typical company, the only system that should be legitimately sending email from the company network is the company's mail server, whether Exchange or some other product. There's rarely any reason to let people inside the network make outbound SMTP connections directly from their desktops or laptops. The biggest reason to block outbound SMTP traffic from end users is to block infected PCs from acting as spam robots. One of the main reasons hackers want to infect PCs is to turn them into robot armies (usually called bots).

    If you block outbound SMTP traffic from all but your official email server, you'll help to neutralize the negative effects from infected PCs. And, if you follow my next step, you'll get an early alert when one of the PCs on your network is infected.

    Controlling outbound email is the low-hanging fruit, but there are other benefits to being stricter on outbound traffic. Should people be using your internal DNS (domain name system) or NTP (network time protocol) servers? If so, then block that outbound traffic to help enforce proper configuration. Do you have devices such as printers or UPSes that should never be talking to the Internet? Block outbound traffic from that portion of your network, and you'll tighten your security profile.

  2. SYSLOG FILTERS CRITICAL FIREWALL LOG DATA
    Firewalls generate tons of data about what's happening on your network, and chances are you aren't looking at any of it. The reason is probably pragmatic: you can't sort out the wheat from the chaff. What's interesting, and what's not? What should you look at and what can you skip?

    You have two options here. One is to tune the firewall itself, so that it only tells you about what's interesting. That may work, and it may not --most firewalls, in my experience, have insufficient knobs to limit the logs to the interesting stuff. The other option is to send the traffic to a tool, such as a SYSLOG server or SEM (Security Event Manager), and then further filter the traffic so you only see what is interesting to you.

    Telling you to install a SEM is probably counter-productive right now, although SEMs are a great way of filtering your security logs. So I'll suggest putting in a SYSLOG server and then writing filters for the interesting traffic. For example, you don't want to see "denied" traffic incoming to your network, because you have that kind of traffic all day long, there's nothing you can do about it, and it isn't worth looking at. However, you definitely do want to see denied outbound traffic because that indicates a problem, such as an end user who isn't following policy, someone inside your network behaving badly, or an infected system.

    In the same vein, look for alerts, such as reaching limits of sessions or memory (typically a sign of an infected system generating massive outbound traffic), denied logins to the firewall from the inside, and any other kind of severe error message your firewall has generated.

    The easiest way to trim this traffic is to summarize it all and then start writing filters to drop out the information you know you don't want, such as allowed connections that are following security policy. After a few hours of looking at logs and dropping the uninteresting parts, you'll find that the unusual and worthwhile information pops out at you quite quickly.

  3. RATE LIMITING CONTROLS EXCESSIVE INBOUND, OUTBOUND TRAFFIC
    Most firewalls have some sort of denial-of-service protections, also called rate limiting. These features keep track of the velocity of connections through the firewall and can limit future connections when the traffic is excessive. Usually firewalls have different limits for inbound and outbound connections, as well as different types of connections (such as UDP connections, typically for tools such as DNS, or TCP connections, which would be more common in email and Web traffic).

    For example, a midmarket company's mail server might see about 1,000,000 incoming (from the Internet) connections a day, counting spam connections, if each of 1,000 employees received 100 messages a day. (Your email server logs should tell you the correct number; I'm just using 1,000,000 as an example.) That's about 10 connections per second. Set your firewall to block more than 20 incoming connections per second and you can both cut down on the amount of spam you get (since spammers often hammer mail servers when they're delivering their evil payloads) and ensure your own mail server doesn't get a sudden burst of mail it can't handle.

    Very high outbound connection rates are another potential sign of problems, since infected desktops and laptops often have very high connect rates towards the Internet as they attempt to re-infect or attack other companies. Using the built-in limiting features of your firewall to help block peak connections both inbound and outbound can shield you from inbound attacks and alert you when internal users are misbehaving, whether intentionally or because of a virus infection.

Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in firewall setup, microsoft tech support, online tech support | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Dial iYogi’s toll free number to access 24/7 online computer repair services.
    With the advancement in the technology each day, the ways of providing customer support have also changed. Now, the Internet has become the ...
  • Intel 8-core 'Nehalem' server processor
    Intel is one of the best company that develops the processors for the computers . All the computer uses the Intel processors for the mothe...
  • Online Virus Scan - iYogi UK
    Online virus scan is an effective tool against virus. This tool can be downloaded from the web browser and after execution it will ensure100...
  • Check the printer's status via the Web
    New printers have their own websites you can check that website for all information related to printers for example printing status, display...
  • Computer Support Services
    Computer support services is a wide gamut of services offering assistance with technology products such as mobile phones, televisions, compu...
  • Complete Antivirus Protection
    Computer viruses are the most dreaded programs, which can corrupt your operating system, destroy your saved data and make your system vulner...
  • Error messages on blue screen, after you install a new hardware device
    This is usually caused by a device driver that doesn’t match the version of Windows on which it is installed. Or some bug in the driver Chec...
  • What to do with Those Old Computer Parts
    Recycling Computers, Monitors, Parts Here in the Valley we have Allied Waste located in Albany, and they will take most of the computers and...
  • Microsoft exchange server installation options
    Microsoft exchanger server is one of the best mailing server . This server is used by the big companies . You can store more data in the exc...
  • How To Enable Shutdown without logging in
    With Windows NT, enabling the shutdown button on the logon screen was as simple as editing the registry at HKEY_LOCALMAC_HINE\SOFTWARE\Micro...

Categories

  • 2009
  • 500 Internal Server
  • 500 Internal Server Error
  • ADODCIT.DLL Errors
  • anti spyware removal
  • anti spyware software
  • anti virus setup
  • antivirus
  • antivirus configuration
  • antivirus installation
  • antivirus installation help
  • antivirus installation support
  • antivirus protection
  • antivirus protection software
  • antivirus setup
  • antivirus solution
  • Antivirus Support
  • Apple needs PC Support
  • Apple’s iPhone
  • backup
  • backup software
  • backup support
  • best computer protection reviews
  • best spyware removal
  • brother printer support
  • browser error
  • browser fix
  • browser problems
  • browser problems uk
  • BROWSER SUPPORT
  • canon printer support
  • computer
  • computer check up
  • computer fix direct
  • computer fix for free
  • computer fix it
  • computer fixing
  • computer help
  • computer help uk
  • computer optimization
  • computer printer repair
  • computer problem
  • Computer problems
  • computer repair
  • computer repair uk
  • computer repairs
  • computer running slow
  • computer support
  • computer support london
  • computer support partner
  • computer support services uk
  • computer support uk
  • computer tech support
  • computer technical support
  • computer troubleshoot
  • Computer troubleshooting
  • computer virus protection
  • computer virus removal
  • computer virus repair
  • computer virus software
  • computers
  • computers support uk
  • create a boot disk
  • create boot disk
  • creating boot disk
  • data backup
  • Data backup support
  • delete office trial
  • dell computer support
  • desktop support uk
  • dll error
  • email help
  • email setup help
  • Exchange Server
  • firewall setup
  • fix a slow computer
  • Fix ADODCIT.DLL Errors
  • FIX BROWSER ERROR
  • FIX BROWSER PERFORMANCE ISSUE
  • fix computer errors
  • fix computer errors free
  • Fix Computer Freezes
  • fix computer problem online
  • fix computer problems
  • Fix Computer Problems free
  • fix computer virus
  • fix computers
  • fix dell computer
  • fix hp computer
  • FIX IEFRAME.DLL BROWSER ERROR
  • FIX INTERNET BROWSER
  • fix laptop computer
  • Fix Msvcr71.dll
  • fix web browser
  • free computer virus protection
  • free Trojan removal
  • free virus removal
  • gmail help
  • green pc
  • hard disk checker
  • hard disk test
  • hard disk testing
  • hard drive recovery
  • harddisk speed test
  • help and support for windows
  • help on email
  • help with internet speed
  • help with the internet
  • hidden file and folder
  • hidden files
  • hidden files and folders
  • hidden files and folders not
  • hidden files and folders vista
  • high speed internet
  • how to create boot disk
  • how to fix computer problems
  • how to outlook
  • how to remove virus
  • how to remove viruses
  • hp computer help
  • hp computer repair
  • hp computer support
  • hp help
  • hp print test page
  • HP printer repair
  • hp support
  • hp tech support
  • hp technical support
  • increase internet speed
  • Install Antispyware
  • install antivirus
  • install printer
  • Internal Server Error
  • internet bandwidth
  • internet connection speed
  • internet explorer 7 problems uk
  • internet speed
  • internet speed optimize
  • it support
  • iYogi
  • January 13
  • lenovo computer support
  • lenovo help
  • Lenovo Support
  • make boot disk
  • Make Your Old Computer New
  • microsoft
  • Microsoft Exchange server
  • Microsoft help
  • microsoft internet explorer repair
  • microsoft office
  • microsoft office help
  • microsoft operating system support
  • Microsoft operating system support uk
  • microsoft support
  • microsoft tech support
  • microsoft technical support
  • Microsoft widows support
  • microsoft window support
  • microsoft windows support
  • microsoft windows update
  • Microsoft windows upgrade
  • microsoft windows windows7 windows 7 microsoft windows 7. windows xp windows vista microsoft vista vista computer support tech support operating system
  • microsoft windows xp support
  • multifunctional printer
  • multifunctional printer repair
  • multifunctional printer support
  • online computer support
  • online computer support uk
  • online hp support
  • online microsoft help
  • online os support uk
  • online pc clean up
  • online pc help uk
  • online pc support uk
  • online spyware removal
  • online tech support
  • online technical support
  • online virus scan
  • online vista support uk
  • online windows help
  • online windows support uk
  • online xp tech support uk
  • operating system installation
  • operating system support
  • optimize computer
  • outlook 2007
  • outlook email
  • Pc check up
  • PC Checkup
  • pc clean up
  • pc computer repair
  • pc health check
  • PC health check up
  • pc optimisation
  • pc optimization
  • pc security
  • pc tech support
  • phone tech support
  • print test page
  • printer installation
  • printer problems
  • printer repair
  • printer support
  • Printer Support 0 comments
  • printer test page
  • printer troubleshooting
  • printing test page
  • processor
  • remote computer help
  • remote computer support
  • Remote PC support
  • remove spyware online
  • remove trojan virus
  • remove virus
  • removing spyware
  • Repair a Computer
  • repair internet connection
  • Server Error
  • server support
  • setting up microsoft outlook
  • show hidden files
  • show hidden files and folders
  • slow computer fix free
  • slow computer performance
  • slow computer problems
  • slow pc problem
  • small business support
  • software
  • spyware
  • spyware removal
  • spyware removal program
  • spyware removal software
  • spyware virus protection
  • support
  • tech
  • tech help
  • tech pc support
  • tech support
  • tech support help
  • tech support uk
  • technical support
  • technical support Tuesday
  • technical support uk
  • test page to print
  • The Role Computer Support Plays in Our Lives
  • Trojan horse
  • Trojan horse removal
  • Trojan horse virus
  • trojan removal
  • trojan removal help
  • Trojan virus
  • trojan virus removal
  • Trojan virus remover
  • troubleshoot microsoft operating system
  • troubleshoot pc errors
  • troubleshooting printer problems
  • uk. computer support uk
  • Uninstall Microsoft Office
  • uninstall microsoft office 2007 vista
  • uninstall microsoft office xp
  • upgrade
  • virus
  • virus protection
  • virus protection software
  • virus removal
  • virus removal software
  • virus scan and removal
  • vista support
  • web browser support uk
  • win xp boot disk
  • window 7
  • window update
  • windows
  • Windows 7
  • windows 7 32-bit direct download
  • windows 7 64-bit direct download
  • Windows 7 Beta
  • windows 7 feature
  • windows 7 support
  • windows 7 taskbar
  • windows automatic update
  • windows email support
  • windows help
  • windows help and support
  • windows live tech support
  • windows print test page
  • windows remote support
  • windows support
  • windows support help
  • windows tech support
  • windows technical support
  • windows troubleshooting
  • windows update
  • windows update xp
  • windows updates
  • Windows Upgrade
  • windows vista help
  • windows xp boot disk
  • windows xp online support
  • windows xp optimization
  • windows xp slow fix
  • windows xp support
  • windows xp updates
  • windows7
  • word 2007 basic
  • word 2007 help
  • word 2007 support
  • xp boot disk

Blog Archive

  • ►  2011 (9)
    • ►  October (1)
    • ►  September (5)
    • ►  August (3)
  • ►  2010 (26)
    • ►  August (1)
    • ►  July (2)
    • ►  April (1)
    • ►  March (11)
    • ►  February (5)
    • ►  January (6)
  • ▼  2009 (88)
    • ►  December (18)
    • ►  November (1)
    • ▼  September (6)
      • Three top firewall tuning tips
      • Increase Your Internet Speed Fast
      • Microsoft Windows Users and iYogi Predict a Surge ...
      • Finding Printer and Other Hardware Installation So...
      • Nokia phones to get Microsoft Office
      • Users keep Microsoft Windows XP alive
    • ►  August (9)
    • ►  July (8)
    • ►  June (7)
    • ►  May (11)
    • ►  April (7)
    • ►  March (6)
    • ►  February (6)
    • ►  January (9)
  • ►  2008 (14)
    • ►  December (7)
    • ►  November (7)
Powered by Blogger.

About Me

Unknown
View my complete profile