Question
November 5, 2007 at 12:48 PM
aaron_wurthmann

Actively Securing a Windows Network from Rouge Systems

by aaron_wurthmann . Updated 18 years, 9 months ago

I think the time has come in this day and age for us all to start to consider the following as fact. People bring systems in from home even though they shouldn’t, people run rouge OSes (Linux, Windows ME, etc) Whilst I have no real problem with Linux (despite my avatar) or any non-Windows OS; I run a Windows only shop, we patch, secure and run Windows only. Anything outside of that is therefore not secured by me. So the question comes down to this…

How do I force all systems on a given network to join the Windows domain and get settings (ISA Client, Windows Firewall, IPSec, 802.11x, or whatever) that only allow Windows Domain clients to talk to Windows servers in the same domain?

Environment Details:
There are currently 4 subnets being routed via a 7i. That can easily be changed to the ISA server doing the workload and later be transitioned to an ISA cluster for redundancy.

Currently an ISA 2006 server sits “behind” the 7i and routes/firewalls all outbound traffic. Behind the ISA server is another firewall and then a router, etc…

All production clients and servers are currently on the same network/subnet/vlan. The other 3 networks are variations of tests networks. The DNS servers in the tests networks have the production DNS servers setup as forwarders. This is required as only the production DNS servers can talk outside for DNS info.

Some ideas I had…
I had this though about using ISA clients distributed via GPO to all production clients and the servers being on a new subnet. Then I could have a rule that said only ISA clients can talk the server subnet on the production/client network. Problem with this however is that there is no intuitive way to set a rule that says something like that. There is a concept of SecureNAT in ISA, but for the like of me I don’t get it. That brings me back to an IPSec policy being pushed via GPO but with the test networks needing to talk to the DNS servers and the WSUS server and possibly the occasional production file server the idea of pushing an IPSec policy scares me a little, as I don’t want to force the test network systems to use a policy I only want to affect the production client network.

Your thoughts? maybe I am missing something totally obvious, maybe someone can explain what ISA SecureNAT clients gives me.

This discussion is locked

All Comments