|
randybridges -> RE: Discussion on HP Appliances (31.Aug.2005 5:53:00 AM)
|
Right after they became available, I recommended that one of my clients purchase the DL320 unit (which I promptly installed for them!). It arrived about 1 week late, but everything was according to spec and setup correctly upon arrival.
After much haggling with the client over implementing a secure rulebase vs. letting the FW stay "open" for web users, I grudgingly left it open for all outgoing web access and locked down the VPN access rules.
Within a month, some pros from the outside did a great job of tearing up the FW, but the unit failed safe - nothing got through. It took five complete passes through the hardware initialization phase before all of the hardware was back to normal and the ISA/OS image could be reapplied. Once that was done, it was business as usual.
After that experience, the client understood WHY we implement a secure rulebase, but they still decided to test our new locked-down rollout... One of the client's employees is married to an FBI data security agent in a nearby city. Unknown to us, the members of his team spent more than 2 weeks trying to break into the firewall and network, without success. Not only did the ISA unit do its job, I was able to alert the client of the attempts and the hacking/probing failure, thus letting them know we were also doing our job. I consider that a good implementation.
Even though it took a long time to return the access to normal, the DL320, the HP configuration tools, the imaging disks and good documentation truly saved the day. While we also install the Network Engines ISA firewall appliance (NS6300/NS6400), I still recommend the HP rollout for environments that need an extra little helping hand.
Randy Bridges
|
|
|
|