User Name Password Register
DaniWeb IT Discussion Community
All
What is DaniWeb IT Discussion Community?
You're currently browsing the Network Security section within the Tech Talk category of DaniWeb, a massive community of 426,924 software developers, web developers, Internet marketers, and tech gurus who are all enthusiastic about making contacts, networking, and learning from each other. In fact, there are 2,365 IT professionals currently interacting right now! Registration is free, only takes a minute and lets you enjoy all of the interactive features of the site.
Please support our Network Security advertiser: Programming Forums
Views: 1748 | Replies: 3
Reply
Join Date: Jun 2006
Posts: 3
Reputation: grindy is an unknown quantity at this point 
Rep Power: 0
Solved Threads: 0
grindy grindy is offline Offline
Newbie Poster

Help locking down access to client data from "outside" hacking.

  #1  
Oct 15th, 2006
My situation is this:
I have a small business with 5 users. Each user can access our clients data from our internal file server. All users are running XP Professional, as is the server machine.
All of us require daily internet access, which is broadband cable behind a router. Each system is running a Security Suite with personal firewall.
What I need to do is be as certain as is "practically" possible that our clients data is not "compromised" from the outside ( via our broadband connection ).
What - if anything - should I add to this setup to be more secure from "outside" hacking?
All comments are certainly appreciated.
AddThis Social Bookmark Button
Reply With Quote  
Join Date: Jan 2006
Location: Tennessee
Posts: 1,567
Reputation: 'Stein is on a distinguished road 
Rep Power: 6
Solved Threads: 102
Colleague
'Stein's Avatar
'Stein 'Stein is offline Offline
Lapsed Skeptic

Re: Help locking down access to client data from "outside" hacking.

  #2  
Oct 16th, 2006
(moved.)
Now if ya like the help ya could always raise our reputation...
Reply With Quote  
Join Date: Apr 2006
Location: Canada
Posts: 4,504
Reputation: John A is a glorious beacon of light John A is a glorious beacon of light John A is a glorious beacon of light John A is a glorious beacon of light John A is a glorious beacon of light John A is a glorious beacon of light 
Rep Power: 17
Solved Threads: 275
Moderator
Featured Blogger
John A's Avatar
John A John A is offline Offline
Vampirical Moderator

Re: Help locking down access to client data from "outside" hacking.

  #3  
Oct 16th, 2006
Originally Posted by grindy
Each system is running a Security Suite with personal firewall.
What I need to do is be as certain as is "practically" possible that our clients data is not "compromised" from the outside ( via our broadband connection ).
What - if anything - should I add to this setup to be more secure from "outside" hacking?
OK, there are a couple of main security models in terms of firewalls.
  • One Internet gateway firewall that's extremely secure, and all the other computers insecure. This is the most common model. Benefits of this model are that security updates only need to done on one system, disadvantages are that once the hacker is in, your whole system is compromised.
  • Firewall is in place on main gateway, but firewalls are also installed on every network client machine. Benefits of this is that it's very secure, disadvantages are that it will become increasingly difficult to maintain security updates on all machine and still keep the network running.
As most people opt for the first one, that's probably the best one to go with. It's still very secure, and like I just said, it's very easy to maintain.

Your router has a built-in firewall, so your router can double as an Internet gateway. However, you might want to consider getting a seperate Internet gateway machine (woud have 2 network cards, one connected to the Internet, and the other connected to the WAN port in the router) that all the data has to pass through before it gets to the router, if you find the router's built-in firewall to limited.

Hope this helps
tuxation.com - Linux articles, tutorials, and discussions
Reply With Quote  
Join Date: Aug 2003
Location: Jersey - You gotta problem wit dat?
Posts: 334
Reputation: TheOgre has a spectacular aura about TheOgre has a spectacular aura about TheOgre has a spectacular aura about 
Rep Power: 8
Solved Threads: 5
TheOgre's Avatar
TheOgre TheOgre is offline Offline
Posting Whiz

Re: Help locking down access to client data from "outside" hacking.

  #4  
Nov 7th, 2006
What kind of router are you using? Is it a cheapo LinkSys/D-Link/Netgear/etc or is it a more robust FIREWALL (Netopia/Cyberguard/etc.)? Do you have access controls in place? Do you allow VPN access into your network (so people can work from home)?

What KIND of data are you trying to protect? Do you fall under GLBA/SOX/HIPAA and are therefor required to meet government regulations for securing data access?


Do you have antivirus installed on all systems? What kind of spyware protection do you have? How are you preventing your inside users from downloading potentially harmful files from the Net that can initiate connections that bring in potentially unsafe content?

Some more details would help..
If you spend more on coffee than on IT security, you will be hacked.
What's more, you deserve to be hacked.
-- former White House cybersecurity czar Richard Clarke
Reply With Quote  
Reply

Only community members can participate in forum threads. You must register or log in to contribute.

DaniWeb Network Security Marketplace
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)

 

Thread Tools Display Modes

Similar Threads
Other Threads in the Network Security Forum

All times are GMT -4. The time now is 11:54 am.
Forum system based on vBulletin Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
©2003 - 2008 DaniWeb® LLC