| » comment | |
| RELATED | MOST POPULAR |
|
First Look: Windows Phone 7
Does your organization run Microsoft Office, Exchange or SharePoint? If so, then you'll want to know about the new features in the soon-to-be-released Windows Phone 7 that will let you collaborate across these programs. Get E-mail Under Control with Personal Archives
Microsoft Exchange Server 2010 provides an alternative to Outlook PST files by offering users a secondary storage area for archiving. The Great Storage Debate
How do businesses know if moving to a SAN makes sense? Pssst: Can You Keep a Secret?
With threats around every corner, companies take steps to effectively secure their data. Making the Switch
Try these tips when planning your Office 2010 deployment. Keep Your Mobile Data Locked Down
Try these five tips to enhance mobile security. Migrating to Windows 7
Which desktop deployment scenario is right for you? Spread the Word
Corporate Traffic, Colony Tire and NCI Building Systems turned to unified communications tools that empower their employees to communicate and collaborate in new ways. Pssst: Can You Keep a Secret?
SMBs take a multilayered approach to security to achieve defense in depth. Making the Switch
Consider these five tips when planning your Office 2010 deployment. |
|

Many decried the Windows Vista firewall as broken when Microsoft released the operating system in 2006 because outbound filtering was turned off by default at the request of enterprise customers. But even in a disabled state, Vista’s firewall does provide limited outbound filtering.
The firewall has three distinct outbound filtering modes. In a disabled state, it uses outbound filtering rules to protect built-in Windows services as part of the service-hardening work undertaken during Vista’s development. The firewall can block outbound traffic from built-in services if unusual behavior is detected. Additionally, certain outbound network messages are blocked to guard against port-scanning attacks.
When you enable outbound filtering, there are standard rules that enable core network functionality. Any additional applications that require outbound access must be added to the rules list. This can be done using the firewall with the Advanced Security Microsoft Management Console (MMC), from the command line or through Group Policy.
Finally, the firewall incorporates Internet Protocol Security (IPsec) rules for authentication and encryption. Domain isolation can be configured to allow PCs joined to an Active Directory domain to send outbound traffic to one another (or to devices specified by systems administrators) and block any other outbound traffic. IPsec domain isolation rules are intended to protect groups of trusted computers, not prevent PCs in a domain from communicating with one another.
Microsoft argues that outbound filtering is not necessary because if a machine becomes infected with malware it might disable the firewall. Although other defense-in-depth mechanisms, such as running standard user and software restriction policies, are more important than filtering, organizations could benefit from the additional protection.
With the exception of a few core networking features, PCs on a corporate network shouldn’t be communicating with one another other, only with designated servers. You can enforce this practice with outbound filtering. This may also help prevent malware from propagating PC to PC, minimizing the spread of malware in the event of a virus outbreak. Without software restriction policies, users can run portable apps that generate unwanted outbound traffic.
Vista’s firewall has three operating profiles — Domain, Private and Public — that apply filter sets for different types of networks. Though it’s possible to assign different firewall profiles to network interfaces, only one profile can be active at a time. The most restrictive profile is always applied, potentially creating access problems for users who are connected to multiple networks simultaneously.
Outbound filtering may be worth setting up on PCs for an additional level of protection, providing extra value with little administrative cost. Although complex outbound rules can be enabled in high-security environments, most organizations should keep it simple and allow most or all outbound traffic to server IP addresses only.
Notebook systems need to be configured and tested more carefully because of the limitations of the firewall in Vista. Windows 7 addresses Vista’s shortcomings by allowing multiple firewall profiles to be active concurrently. (Read the BizTech article.)
Russell Smith is an independent consultant based in the United Kingdom who specializes in Microsoft systems management.