|
Whilst we pride ourselves on building hardened
servers, for the ultimate in security you need a hardware based
firewall. We use the SonicWALL range of firewalls which have been
independantly certified by ICSA
Labs
The firewall will be configured to your
individual requirements rather than using a set of generic templates.
The default setting is deny-all so we open up only ports which are
required. A basic linux box would only require ports 22 and 80/443
for SSH access and webserving for example. We can even configure
different rules for different IP addresses on the same server.
To see the results of a penetration test a customer
ran against one of their boxes, click here.
- ICSA-Certified Stateful Packet Firewall
The PRO 3060 adheres to industry standards for enterprise-class
firewall protection with ICSA-certified, stateful packet
inspection technology.
- Integrated ICSA-Certified IPSec VPN
The PRO 3060's enterprise-class VPN support delivers fast,
secure access to resources.
- AutoUpdate Security
The autoupdate ensures that the firewall is kept current
with the latest protection and updates.
- Powerful Architecture with security ASIC
Built on SonicWALL's security ASIC, the PRO 3060
delivers breakthrough performance with hardware-acceleration
for superior VPN and security throughput
|
|
As well as preventing hackers from port scanning
(A port scan will not reveal the port as open or
closed - it will be classed as unknown due to the stealth functionality)
and detecting what operating system you are running the firewalls
will block all known DOS attacks including :
SYN Flood - This attack involves
sending connection requests to a server, but never fully completing
the connections. This will cause some computers to get into a "stuck
state" where they cannot accept connections from legitimate
users. ("SYN" is short for "SYNchronize"; this
is the first step in opening an Internet connection).
Ping Of Death - This attack involves sending unexpectedly
large packets to a machine. This can cause unpredictable results
which can include actually crashing the server.
IP Spoofing - This attack involves using fake
source addresses for Internet data, thus tricking internal machines
into thinking that data from the Internet was actually generated
locally. This is analogous to using a bogus return address on a
posted letter in order to conceal its origin. It can be used to
do things such as issuing fake instructions to machines on the LAN.
LAND Attack - This is actually a specific type
of spoofing attack, where the source address information is the
same as the destination address information. This will confuse some
operating systems, causing them to crash.
Smurf Amplification - "Smurf attacks"
involve using an intermediate network to generate huge amounts of
traffic to the victim network. This traffic clogs up the victim's
Internet connection. Although there is really no way for a firewall
to prevent bandwidth saturation, SonicWALL will keep your network
from being used to attack others. |