PDA

View Full Version : Security Issue


shahzad_aijaz
May 11th, 2004, 06:04 AM
My network includes Proliant ML370 G3 server and 10 normal PCs. This
server will not be online all the time but only when necessary for
normal updates and stuff like that.
Can anyone suggest me that what Security product I should use on my
server to prevent external intrusions and virus threats?
Symantec or any other third party Security product and why ?

Paranoid2000
May 11th, 2004, 09:14 AM
Welcome to the forum Shahzad_aijaz,

While I have used Symantec in the past I would be strongly inclined to avoid them now - the incorporation of Product Activiation can cause problems when you least need them (e.g. finding that you have to reactive when trying to boot a hosed system off floppy in order to do a virus scan). Also recent versions of their products have suffered from severe bloat, taking far more memory/disk space than they should.

Basic protection would be a virus scanner (frequent recommendations include NOD32 or KAV) and a firewall (ZoneAlarm for simple filtering, Outpost or Kerio for more sophisticated rules setup). See the Wilders' pages on anti-viruses (http://www.wilders.org/anti_viruses.htm) and firewalls (http://www.wilders.org/firewalls.htm) for more options and information. In your case, consider using a hardware firewall to filter incoming traffic and a software firewall on each PC to detect and block any malware/spyware trying to send data out (your hardware firewall cannot detect this since it has no way of knowing what application is sending data on your PCs).

Also use a web content filter to block ActiveX, Java and Javascript to avoid browser hijacks and other website unpleasantness (included in firewalls like Outpost and Kerio) and a spyware/adware (http://www.wilders.org/spyware.htm) scanner.

If your network is being used for P2P, Usenet or IRC then you are at increased risk of picking up malware - consider specialised anti trojan (http://www.wilders.org/anti_trojans.htm) software at this stage.