Showing posts with label PBX Firewall. Show all posts
Showing posts with label PBX Firewall. Show all posts

Thursday, October 7, 2010

Inside-Out Firewalling

The deployment of perimeter firewalls is the most fundamental element of any business network. Most organizations have outside to inside (outside-in) firewalling that prevents all but a limited range of legitimate traffic into the "demilitarized zone" (DMZ) or internal networks. The obvious benefit of this is that outside-in firewalling protects the company from attacks that originate from the outside. Ports that are typically opened are HTTP and secure socket layer (SSL) for Web traffic, domain name service (DNS) ports for resolution of IP addresses, e-mail ports, remote access connections, and a handful of other necessary business-to-business communication (file transfer or virtual private network) protocols.


Add a note hereHowever, the adoption of inside to outside (inside-out) firewalling is not as prevalent. Many companies have limited or no inside-out firewall rules, thus allowing broad access for outbound connections from within their corporate network to the outside world. A cost-efficient way to hinder the effectiveness of malware significantly is to focus on implementing inside-out firewalling. You already own the firewalls, so stretch your investment dollars by configuring them to enable the following:

§  Add a note hereBlock viruses from spreading from one segment of your network to another or from your network to other companies, thus limiting your liability and containing the exponential propagation of the virus.
§  Add a note hereLimit the ability for automated attacks to download more tools from the Internet.
§  Add a note herePrevent spyware, zombies, or bots from establishing contact or sending data to their controllers (person or group who collects or controls the malware).
§  Add a note hereEnforce stronger end-user policies to limit business-only access from inside your network to the Internet. This in turn should lower your infection rate as well as curb undesirable, unproductive, and potentially malicious behavior.

Add a note hereTo facilitate inside-out firewalling, activate firewall monitoring to see the range of traffic going to the Internet from your network. You will be surprised to find the amount of nonbusiness-related and potentially malware-associated activities traversing your perimeter. From the firewall logs, establish and enforce your policies around a limited range of business- and IT-sanctioned activities such as Internet browsing, DNS resolution, network time protocol (NTP), and so on.

Add a note hereInside-out firewalling is not a silver bullet, but rather another layer of defense that you can leverage without additional hardware. Sophisticated malware writers still get around these controls by tunneling their traffic through legitimate inside-out ports such as HTTP or even SSL. Talk to your firewall vendors about how your specific firewall can counter the inside-out threats that use legitimate ports.

Monday, May 18, 2009

PBX Firewall

In recent years, PBX firewall technology has been increasingly used by military installations, hospitals, energy firms, banks, and others to dramatically increase their control of telecommunications traffic. In some cases, the increased reporting available from the firewall has enabled them to reduce costs as well.

How does it work? A series of very fast, special-purpose computers sit between the "demarc" wiring from the telephone company and the PBX. These pizza box size computers have the unique ability to look inside the traffic on the telecommunications lines and apply predefined, logical rules. For example, the PBX firewall can:

  • Stop or log unauthorized modem traffic (e.g., individuals may set up PCAnywhere on their workstations as a convenience, unintentionally leaving a backdoor for hackers).

  • Stop modem traffic detected on lines that are supposed to be for fax-only. The same event could also trigger logging-only or a page to security personnel.

  • Stop voice traffic on fax lines after a certain time at night. Or limit calls to no more than three minutes (time to communicate with a distant party regarding fax status).

  • Report on any lines not used in the past six months.

  • Page or show exception reports when anyone in the organization calls a direct competitor.

  • Disable any calls to or from ISPs not relevant to the organization's business.

  • Provide special-purpose reporting on individual lines, odd usage, traffic between company locations, etc.

Exhibit 5 illustrates how hackers often thwart a strong IT firewall. Hackers, like most others, first look for the easy way in.

The PBX firewall, shown in Exhibit 6, sits between the demarc and the PBX, significantly lessening the likelihood of unauthorized intrusion (assuming the appropriate logic rules have been programmed).


Savings Potential Using PBX Firewall

The detailed information gathering and reporting available from the PBX firewall can potentially result in cost reduction. In a case study reported by Memorial Hermann Hospital in Houston, Texas, significant savings were obtained from:

  • Elimination of unauthorized modem calls to ISPs, freeing up trunk lines for voice communications so that installation of new T1s could be eliminated or at least delayed.

  • Replacement of higher-cost local access trunks with cost-effective tie trunks. By identifying that much of the PSTN traffic was between Memorial Hermann locations, it was easy to justify fixed cost tie lines that proved to be less-expensive, even in the short run. Three local access trunks costing a total of $4500 per month were replaced with three tie lines at $1050 per month, resulting in a savings of $3450 per month.

  • Reduction of full-time equivalent employee costs. The higher visibility of telecom information plus the ability to centrally monitor the entire Memorial Hermann enterprise resulted in decreased telecom FTEs per end user.

Another cost savings was reported by an East Coast banking enterprise. The telecom organization within the bank installed a PBX firewall for a few weeks at each of several locations. When the traffic patterns were recorded at one location, the firewall was moved to another site. After the round-robin process was complete, the bank had identified enough unused capacity to justify the firewall purchase several times over.