Firewall Wizards mailing list archives
question on securing out-of-band management
From: "golovast" <golovast () yandex ru>
Date: Fri, 3 Feb 2006 11:38:45 +0300 (MSK)
A few words about the network. It is a environment where security is of a highest priority, because customer data is handled and a variety of regulations apply. Just like everyone else, we want to make the network reliable, secure, scalable, etc. We have decided to use out-of-band management for the perimeter servers. It will be done over a dedicated Ethernet interface. Servers are mostly microsoft, network gear is mostly cisco. I have two questions. First, did anyone here ever try using USB ethernet adapters for OOB in perimiter and high performance servers? A lot of servers don't have extra NICs. Sticking in USB adapters would be a lot easier, but I am still a bit hesitant. Internal NICs would be preferable, but its a lot of manual labor and downtime. Any big cons against using usb ethernet? Second question is about security. How do you secure the oob management network? It obviously has it's pros, but even still it's a good way to bypass all other security layers. I was thinking about HIDS and locking things down with ACLs and hardening servers. Also, no ports on the floor assigned to that network and a VPN access with two-factor authentication into it. Am I leaving anything out? How are you guys doing it? What are the other alternatives? I'll appreciate any replies. Thanks. _______________________________________________ firewall-wizards mailing list firewall-wizards () honor icsalabs com http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
Current thread:
- question on securing out-of-band management golovast (Feb 03)
- RE: question on securing out-of-band management Paul Melson (Feb 07)
- Re: question on securing out-of-band management Marcus J. Ranum (Feb 07)
- Re: question on securing out-of-band management Kevin (Feb 07)
- <Possible follow-ups>
- RE: question on securing out-of-band management Brian Ford (brford) (Feb 07)
- RE: question on securing out-of-band management golovast (Feb 07)
- Re: question on securing out-of-band management Kevin (Feb 07)
- Re: question on securing out-of-band management golovast (Feb 07)
- Re: question on securing out-of-band management R. DuFresne (Feb 09)
- RE: question on securing out-of-band management golovast (Feb 07)
- RE: question on securing out-of-band management (ver. 2) golovast (Feb 07)
- RE: question on securing out-of-band management (ver. 2) Marcus J. Ranum (Feb 07)
