Re: Firewall confusion



On Mon, 28 Dec 2009 13:11:43 +0100, houghi <houghi@xxxxxxxxxxxxxxxxxx>
wrote:

Stephen Horne wrote:
Just for the record, though, which of the following would your little
sister be better equipped to cope with...

1. Answering "Thunderbird wants internet access - yes or no?"

2. Configuring the OpenSUSE firewall.

Neither. System access should NOT be done on a user level. Not by me
and not by my little sister.

To me there is a HUGE difference between "Me, the user" and "Me, the
system administrator"

And this means that you can never decide which applications should be
allowed to access the internet, irrespective of which hat you happen
to be wearing?

Why?

I repeat - I'm not asking to clone ZoneAlarm or the Windows way. I
just want to prevent applications from accessing the internet without
my explicit permission. I'm quite happy to make those whitelisting
decisions while wearing my system admin hat, and I agree that it's a
necessity for the thing to really be secure.

But even if blocking/unblocking internet access was done with no admin
password needed, as is generally the case on home Windows boxes, it's
still more secure than *always* allowing *all* applications to access
the internet.

.



Relevant Pages

  • RE: Group Policy - Restrict Internet Access by OU?
    ... you could not find ISA on SBS 2003, you can use SBS premium technology disk ... to install ISA server. ... restrict internet access on special user group. ...
    (microsoft.public.windows.server.sbs)
  • RE: ISA 2004 - Internet Access without using Firewall Client
    ... you can not install ISA firewall client on mobile laptops but meanwhile ... we can make the laptops to access Internet without ... ISA server on SBS only allows domain user access Internet. ... How to configure Internet access in Windows Small Business Server 2003 ...
    (microsoft.public.windows.server.sbs)
  • Re: SBS ISA2004 allows all users internet access, why?
    ... > Did you try making a new rule in ISA 2004 after the upgrade? ... > changes the users that I put in that group could not access the Internet. ... >>> internet access what difference does it make whether All User or SBS ...
    (microsoft.public.windows.server.sbs)
  • Re: SBS ISA2004 allows all users internet access, why?
    ... allowed in the SBS Internet Access Rule in ISA2004? ... >> internet access what difference does it make whether All User or SBS ...
    (microsoft.public.windows.server.sbs)
  • Re: ISA 2004 - Redirect HTTP Requests to different web page
    ... The end result I need is a few users to have unrestricted internet access ... In Windows 2003 SBS I created a Window Security Group in Active Directory ... client can access but it will not redirect to any url. ...
    (microsoft.public.windows.server.sbs)