Server Security Question

%3CLINGO-SUB%20id%3D%22lingo-sub-654476%22%20slang%3D%22en-US%22%3EServer%20Security%20Question%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-654476%22%20slang%3D%22en-US%22%3E%3CP%3EI%20work%20for%20small%2Fmedium%20size%20firm%20and%20have%20been%20made%20responsible%20for%20IT%20related%20matters.%20We%20have%20a%20local%20IT%20partner%20who%20manages%20all%20our%20employee%20laptops%20and%20our%20server.%20I've%20been%20asking%20questions%20about%20our%20server%20security%20and%20something%20does%20seem%20right%20to%20me.%20Is%20it%20possible%20and%2For%20close%20to%20best%20practice%20to%20use%20the%20domain%20controller%20as%20our%20firewall%20i.e.%20not%20install%20a%20firewall%20as%20the%20rules%20on%20the%20domain%20controller%20can%20keep%20us%20secure%3F%20Appreciate%20any%20feedback.%20Thanks%20in%20advance.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-657974%22%20slang%3D%22en-US%22%3ERe%3A%20Server%20Security%20Question%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-657974%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F350912%22%20target%3D%22_blank%22%3E%40EdwardL%3C%2FA%3E%26nbsp%3B-%20I%20Spent%2010%20years%20working%20for%20a%20Managed%20Services%20Provider%20servicing%20SMBs%20and%20the%20Mid-Market%20specifically%20and%20it%20was%20our%20standard%20practice%20to%20ALWAYS%20install%20a%20firewall%20appliance%20(Like%20a%20Watchguard)%20at%20every%20location.%20Most%20modern%20routers%20will%20have%20some%20sort%20of%20rudimentary%20firewall%2C%20but%20they%20usually%20can't%20hold%20a%20candle%20to%20a%20dedicated%20firewall%20appliance.%20It's%20possible%20your%20IT%20support%20is%20relying%20on%20the%20router's%20firewall%2C%20or%20maybe%20has%20just%20neglected%20to%20mention%20that%20there%20is%20a%20firewall%20appliance%20in%20place.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIf%20your%20IT%20support%20is%20telling%20you%2C%20you%20don't%20need%20a%20firewall%20because%20your%20domain%20controller%20is%20keeping%20you%20safe%2C%20I%20would%20question%20it.%20Your%20Domain%20Controller%20is%20providing%20identity%20and%20authentication%20services%20(username%2Fpassword)%20for%20your%20network%2C%20while%20a%20proper%20firewall%20appliance%20is%20designed%20to%20keep%20the%20bad%20people%20off%20your%20network%20to%20begin%20with.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ECould%20be%20they%20are%20relying%20on%20the%20in-software%20Windows%20Firewall%20on%20each%20server%2Fworkstation%20to%20do%20the%20work%2C%20but%20best%20practice%20would%20state%20you%20don't%20even%20want%20attackers%20to%20be%20able%20to%20reach%20an%20endpoint.%20Hence%2C%20a%20firewall%20appliance%20at%20the%20entry-point%20of%20the%20network.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EI%20say%20this%20without%20knowing%20more%20specific%20information%20about%20your%20environment%2C%20but%20based%20on%20what%20you've%20said%20I%20would%20at%20least%20question%20it%20and%20try%20to%20get%20some%20more%20information%20from%20them.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-663502%22%20slang%3D%22en-US%22%3ERe%3A%20Server%20Security%20Question%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-663502%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F63998%22%20target%3D%22_blank%22%3E%40Andy%20Syrewicze%3C%2FA%3E%26nbsp%3BThanks%20Andy%2C%20yes%2C%20you%20are%20correct%20our%20IT%20provider%20is%20suggesting%20that%20the%20domain%20controller%20will%20authenticate%20all%20traffic%20so%20no%20need%20for%20a%20firewall.%20Given%20I'm%20far%20from%20an%20expert%20I'm%20just%20not%20sure%20I%20can%20sleep%20at%20night%20with%20merely%20a%20domain%20controller%20for%20protection..%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
New Contributor

I work for small/medium size firm and have been made responsible for IT related matters. We have a local IT partner who manages all our employee laptops and our server. I've been asking questions about our server security and something does seem right to me. Is it possible and/or close to best practice to use the domain controller as our firewall i.e. not install a firewall as the rules on the domain controller can keep us secure? Appreciate any feedback. Thanks in advance. 

2 Replies
Highlighted

@EdwardL - I Spent 10 years working for a Managed Services Provider servicing SMBs and the Mid-Market specifically and it was our standard practice to ALWAYS install a firewall appliance (Like a Watchguard) at every location. Most modern routers will have some sort of rudimentary firewall, but they usually can't hold a candle to a dedicated firewall appliance. It's possible your IT support is relying on the router's firewall, or maybe has just neglected to mention that there is a firewall appliance in place. 

 

If your IT support is telling you, you don't need a firewall because your domain controller is keeping you safe, I would question it. Your Domain Controller is providing identity and authentication services (username/password) for your network, while a proper firewall appliance is designed to keep the bad people off your network to begin with.

 

Could be they are relying on the in-software Windows Firewall on each server/workstation to do the work, but best practice would state you don't even want attackers to be able to reach an endpoint. Hence, a firewall appliance at the entry-point of the network. 

 

I say this without knowing more specific information about your environment, but based on what you've said I would at least question it and try to get some more information from them. 

Highlighted

@Andy Syrewicze Thanks Andy, yes, you are correct our IT provider is suggesting that the domain controller will authenticate all traffic so no need for a firewall. Given I'm far from an expert I'm just not sure I can sleep at night with merely a domain controller for protection..