Intrusion management Questions


Pix Firewall and Proxy Server
I need to allow only one IP address (the one for proxy server) to browse through Pix firewall to Internet. What will be the commands in PIX firewall to block the traffic to Internet from all the network 10.2.1.x but only allow 10.2.1.10 (Proxy server). All other computers will use proxy server address to use [...]

Answer Question   |  September 25, 2005  1:49 PM
Access control, Application security, backdoors, Biometrics, Browsers, Compliance, configuration, CRM, Current threats, Database, Digital certificates, Disaster Recovery, Encryption, Exchange, filtering, Firewalls, Forensics, Hacking, human factors, Identity & Access Management, Incident response, Instant Messaging, Intrusion management, Network security, Networking, patching, PEN testing, Platform Security, Policies, provisioning, Risk management, Secure Coding, Security, Security Program Management, Security tokens, Servers, Single sign-on, Spyware, SSL/TLS, Tech support, Trojans, Viruses, VPN, vulnerability management, Web security, Wireless, worms
asked by:
0 pts.

Prefferred Anti Virus Program?
Hi All, Can i get any suggestions on what you consider being the BEST Anti virus software with not much hassles! The 2 i`m most interested in is Norton and Mcafee? Any 3rd party app will also be greatly appreciated! I had Norton 2005 Internet Security on my PC,1.7GHZ AMD,Win XP SP2, 384MG RAM and [...]

Answer Question   |  October 14, 2005  6:10 AM
Access control, Application security, Automated, Availability, backdoors, Bandwidth, Billing and customer care, Billing Support Systems, Biometrics, Browsers, Career development, Compliance, configuration, CRM, Current threats, Data analysis, Data warehousing applications, Database, DataCenter, Desktop management applications, Development, Digital certificates, Disaster Recovery, Ecommerce applications, Encryption, ERP, Exchange, filtering, Firewalls, Forensics, Functional, Geographic information systems applications, Hacking, HEAT, Help Desk, human factors, Identity & Access Management, Incident response, Instant Messaging, Intrusion management, Lifecycle development, Manufacturing applications, McAfee, Microsoft Windows, Network security, Networking, patching, PEN testing, Performance/Load, Platform Security, Policies, provisioning, Risk management, Routers, Secure Coding, Security, Security Program Management, Security tokens, Servers, Single sign-on, Software, Software testing, Software testing tools, Spyware, SSL/TLS, Symantec, Systems management software, Tech support, Trojans, Viruses, VoIP, VPN, vulnerability management, Web, Web security, Wireless, worms
asked by:
0 pts.

Disable ‘Always On’ Firewall Option Cisco VPN Client / 3000 Series Concentrator
Hi, A network engineer that left our company enabled the Always On Firewall option on our Cisco VPN 3000 Series Concentrator and I don’t know how to disable it? What I actually want to do is setup a specific group that has is disabled, and leave the other existing groups with the option set. Thanks, [...]

Answer Question   |  September 22, 2005  5:45 AM
Cisco, Firewalls, Forensics, Incident response, Intrusion management, Network security, Networking, Routers, VPN, Wireless
asked by:
0 pts.

Need Help – Netscreen 25 with Fortigate 60.
Hi All. Good Morning & Greetings of the season. I recently joined this company as a Network Security Specialist & the 1st task that i got assigned to myself was this. We have 3 locations – A (India) – Indian Operations B (California) – US Operations C (Datacenter) – Web & Media Servers My network [...]

Answer Question   |  October 27, 2005  10:05 AM
Access control, Application security, backdoors, Biometrics, Browsers, Cabling, Compliance, configuration, CRM, Current threats, Database, Digital certificates, Disaster Recovery, Encryption, Exchange, filtering, Firewalls, Forensics, Hacking, Hardware, Hubs, human factors, Identity & Access Management, Incident response, Instant Messaging, Intrusion management, Juniper Networks, Network security, patching, PEN testing, Platform Security, Policies, provisioning, Risk management, Routers, Secure Coding, Security, Security Program Management, Security tokens, Servers, Single sign-on, Spyware, SSL/TLS, Switches, Trojans, Viruses, VPN, vulnerability management, Web security, Wireless, worms
asked by:
0 pts.

windows network file sharing and authentication ports
I have a requirement for remote users (non-member windows clients) connected via a MPLS network to connect a network file share. I would like to know which ports I need to open on the firewall for filesharing and active directory authentication? Also I am going to be using the destination ip addresses to control access [...]

Answer Question   |  October 17, 2005  9:26 AM
Firewalls, Forensics, Incident response, Intrusion management, NetBIOS, Network security, TCP, VPN, Wireless
asked by:
0 pts.

has anyone had issues with appliances getting cracked?
We have a mcafee anti-virus and anti-spam appliance. We used it as out internet email presence and as a web proxy. All email comes in thru it and all web traffic from our internal web proxy went thru it. The web proxy is limited to less than half of the internet bandwidth. It is behind [...]

Answer Question   |  September 27, 2005  7:02 PM
Access control, Application security, backdoors, Browsers, configuration, Current threats, Database, Encryption, Exchange, filtering, Firewalls, Forensics, Hacking, human factors, Incident response, Instant Messaging, Intrusion management, Network security, patching, PEN testing, Platform Security, Secure Coding, Servers, Spyware, SSL/TLS, Trojans, Viruses, VPN, vulnerability management, Web security, Wireless, worms
asked by:
0 pts.

Remote Desktop outbound connection fails
I have an ISA Server 2000 and Windows 2000 Small Business Server Edition. I can connect to a external (Internet) Terminal Server from the ISA firewall computer, but I can not connect from the internal Workstations, which have the Firewall Client installed. I already enabled the RDP (Terminal Services) protocol in the ISA firewall and [...]

Answer Question   |  September 13, 2005  5:30 PM
Firewalls, Forensics, Incident response, Intrusion management, Network security, VPN, Wireless
asked by:
0 pts.

problems with wireless connection on firewall
Hi, I have a “firewall”-box configured as NAT-router/firewall/transparent proxy which makes a connection to the internet with a WLAN card (to a hotspot). In fact for the moment it’s a Kerio Winroute firewall on a Wintel box. So the “firewall”-box has actually 2 interfaces. One wired (connected to the internal LAN) and one USB wireless [...]

Answer Question   |  September 9, 2005  3:52 AM
Firewalls, Forensics, Incident response, Intrusion management, Network security, VPN, Wireless
asked by:
0 pts.

Can connect by VPN but cannot ping internal addresses
My director and I have set up a SmoothWall firewall with SmoothTunnel VPN in our office. We have created L2TP road warrior connections for our Win XP clients at home and we can both successfully connect via our individual VPN tunnels. However, whereas I can ping the decimal addresses of the internal firewall NIC and [...]

Answer Question   |  September 6, 2005  2:42 PM
Firewalls, Forensics, Incident response, Intrusion management, Network security, VPN, Wireless
asked by:
0 pts.

Windows 2000 Server logs
Hi All, Basically i want to monitor all the activities of my administrators. Is there any way I can find out all the activities on a Windows 2000 Server eg:- success / failure logs ,which users had logged on to a server , user creation time ,service stopped at what time, what scripts have been [...]

Answer Question   |  September 16, 2005  6:17 AM
Access control, Application security, backdoors, Biometrics, Browsers, Compliance, configuration, CRM, Current threats, Database, DataCenter, Digital certificates, Disaster Recovery, Encryption, Exchange, filtering, Firewalls, Forensics, Hacking, human factors, Identity & Access Management, Incident response, Instant Messaging, Intrusion management, Network security, patching, PEN testing, Platform Security, Policies, provisioning, Risk management, Secure Coding, Security, Security Program Management, Security tokens, Servers, Single sign-on, Spyware, SSL/TLS, Trojans, Viruses, VPN, vulnerability management, Web security, Wireless, worms
asked by:
0 pts.

IT Security
Hi all, Thanks to all those who answered to my question”FTP sites” Can anyone of you let me know about the available products that we can use for our organisations IT security..Also let me know what products are available to find out vulnerabilities in a network. Appreciate your response. Thanks Tarang

Answer Question   |  August 27, 2005  6:03 AM
Access, Access control, Application security, backdoors, Biometrics, Browsers, Certifications, Compliance, configuration, CRM, Current threats, Database, Desktops, Digital certificates, Disaster Recovery, E-business, Encryption, Exchange, filtering, Firewalls, Forensics, Hacking, human factors, Identity & Access Management, Incident response, Instant Messaging, Intrusion management, Management, Microsoft Office, Microsoft Windows, Network security, Networking, OS, patching, PEN testing, Platform Security, Policies, provisioning, Risk management, Secure Coding, Security, Security Program Management, Security tokens, Servers, Single sign-on, Spyware, SQL Server, SSL/TLS, Trojans, Viruses, VPN, vulnerability management, Web security, Wireless, worms
asked by:
0 pts.

Securing FTP on an Enterprise wide basis
One of the recent questions here in the SeachWindowsSecurity.com ITKnowledge Exchange was stated the poster had blocked email services with a Proxy server so that internal employees could not obtain yahoo, AOL, and other external sources of security threats and the poster wanted further support in blocking FTP websites or locations. I know that in [...]

Answer Question   |  August 25, 2005  2:44 PM
Application security, Database, Encryption, Exchange, Firewalls, Forensics, Incident response, Instant Messaging, Intrusion management, Network protocols, Network security, Secure Coding, Security, TCP, VPN, Wireless
asked by:
0 pts.

Bad logon Event type 529
A User ill advisedly switched off Anti-Virus and since then we see a failed logon (Type 4 – Batch)under Logon process Advapi every 15 minutes in his User Id. A search of the Web links this to possible virus infectection (Netdevil 1.2. We have scanned etc but can’t track down what is generating the attempted [...]

Answer Question   |  August 25, 2005  7:11 AM
Access, Access control, Application security, backdoors, Browsers, Current threats, Database, Desktops, Encryption, Exchange, filtering, Firewalls, Forensics, Hacking, human factors, Incident response, Instant Messaging, Intrusion management, Management, Microsoft Windows, Network security, OS, Patch management, Secure Coding, Security, Servers, Spyware, SQL Server, SSL/TLS, Trojans, Viruses, VPN, Web security, Wireless, worms
asked by:
0 pts.

Local Admin & passwords
We have recently switched to allowing only Power User rights on notebook computers. We have a set of notebooks we loan out to employees with desktops when they need to travel. Currently those users will login with an account named loaner and use scripts and webmail to access the network. Discussion has come up recently [...]

Answer Question   |  August 19, 2005  3:52 PM
Application security, Biometrics, Compliance, configuration, CRM, Database, Digital certificates, Disaster Recovery, Encryption, Exchange, Firewalls, Forensics, Identity & Access Management, Incident response, Instant Messaging, Intrusion management, Network security, patching, PEN testing, Platform Security, Policies, provisioning, Risk management, Secure Coding, Security, Security Program Management, Security tokens, Single sign-on, VPN, vulnerability management, Wireless
asked by:
0 pts.

Remote Desktop conflicts with VPN
I am connecting using Remote Desktop from my Laptop PC (Windows 2000 Pro Sp4) to a Server (Windows 2000 Server Sp4) in our DMZ over our Corporate Network. I am then using a Network & Dialup Connection on the Remote Server to connect over VPN to our Customer Sites. However, this is currently unusable as [...]

Answer Question   |  August 30, 2005  10:08 AM
Availability, Cabling, Desktop management applications, Ethernet, Fault isolation, Firewalls, Forensics, Hardware, Hubs, Incident response, Intrusion management, Microsoft Windows, Network applications management, Network management software, Network monitoring, Network protocols, Network security, Network testing, Networking, Performance management, Protocol analysis, Remote management, Routers, Software, Switches, TCP, VPN, Wireless
asked by:
0 pts.

asked by:
0 pts.

asked by:
0 pts.

Symantec Anti Virus Corporate 8.0 issue
Starting one WinXPSP2 (fully patched) computer last night revealed that the SAV Corporate 8.0 was not functioning properly (yellow “!” over systray icon). Restart of the computer did not resolve the issue. I cannot update (Live Update is disabled); I cannot uninstall (process appears to start and then simply dies/quits without error or error message [...]

Answer Question   |  February 8, 2008  9:07 AM
backdoors, Current threats, Firewalls, Forensics, Hacking, Help Desk, human factors, Incident response, Installation, Intrusion management, Network security, Norton, Security, Spyware, Symantec, Tech support, Third-party services, Trojans, Viruses, VPN, Wireless, worms
asked by:
0 pts.

Blocking Tunneling Applications
Hi; Any suggestions on how I can block hopster(and other similar socks based tunneling applications)from tunnelling out and bypassing the firewall? When hopster contacts its servers it uses different set of IPs, not a single domain, so its kind of hard to block it based on IPs Thank You

Answer Question   |  August 1, 2005  1:28 AM
Application security, Database, DataCenter, Encryption, Exchange, Firewalls, Forensics, Incident response, Instant Messaging, Intrusion management, Network security, Networking, Secure Coding, Security, VPN, Wireless
asked by:
100 pts.

aaa authorization ?
Which of the following authorization commands are valid? (we have to choose 2 correct) A. aaa authentication exec home radius B. aaa accounting exec home radius C. aaa authorization default none D. aaa authorization exec home radius E. aaa authorization network default enable F. aaa authorization network default local

Answer Question   |  July 26, 2005  9:45 AM
Administration, Application security, Architecture/Design, Biometrics, Cabling, Cisco, Data analysis, Database, DataCenter, Desktop vs network-based firewalls, Digital certificates, Documentation, Encryption, Exchange, Features/Functionality, Firewalls, Forensics, Hardware, Hubs, Identity & Access Management, Incident response, Installation, Instant Messaging, Intrusion management, Network security, Networking, Product/Service evaluation, provisioning, Routers, Secure Coding, Security, Security tokens, Service and support, Single sign-on, Switches, VPN, Vulnerability Assessment & Audit, Wireless
asked by:
0 pts.