UTM Devices - Bit of advice.

Soldato
Joined
9 Jan 2007
Posts
2,760
Location
Gibraltar
Morning peeps.

Ok, had a bit of an "intrusion" at work on monday, of which the fallout has been to look at the possibilty of installing a Unified Threat Management device on our network.

As it stands, the network is roughly comprised of the following:

800 Client (XP & Win7) machines running Sophos AV/IDS
40 Servers, mostly Windows 2008/r2, few linux, few iSeries machines.
Websense internet filtering server
Sophos mailgateway taking care of our email spam/etc.

All machines access the internet via one gateway (4meg internet connection), which passes through a Cisco ASA firewall, which unfortunately is not fully managed by us (local ISP, which is 50% owned by organization I work for, does the management and config at our request).

Im not too clued up on UTM/IDS/IPS systems, but ideally what we're looking for is an appliance which sits behind the firewall (inside our network - therefore we would config it) which would scan all traffic flowing into and out of the network. I've briefly read up and have seen that some of these systems can scan traffic and then setup a baseline in order to flag up any new/suspicious activity.

That's as far as my knowledge on the subject goes. Any tips? Manufacturer suggestions? Budget as always is low, probably highest I can spend would be £10k and under. Can provide more information if needed :)
 
Well if you're happy with the firewall you just need an IDP device, UTM typically combines a firewall and IDP into one box. I recommend Juniper for most security related products and their IDP range is as good as any mainstream manufacturers.

That said, not that many people need UTM if they've got a firewall set up correctly and remote access policies sensibly defined....
 
Yep, pretty happy with the firewall to be honest. Already relatively clued up on Juniper systems as we have a Juniper SSL box in place at the moment.

Cheers, will look into the IDP route.
 
Yep, pretty happy with the firewall to be honest. Already relatively clued up on Juniper systems as we have a Juniper SSL box in place at the moment.

Cheers, will look into the IDP route.

Just out of interest then, how did they get in ?

Wireless network ?
 
Just out of interest then, how did they get in ?

Wireless network ?

Cant really say on the net, sorry. Lets just say certain admin privelidges needed to be reviewed, and a certain server which was unrestricted in websense (for operational reasons), was used to do some naughty things. That whole admin rights issue has been sorted, much heavier auditing has been put in place, and the server in question has been reviewed.

Still, an IDP is on the cards as I feel the network (and content) is big and important enough to justify the IT staff having more tools at their disposal to monitor any similar problems in the future. Usual funding/awareness problems abound though :(
 
Back
Top Bottom