techPowerUp! Forums

Go Back   techPowerUp! Forums > Hardware > Networking & Security

Reply
 
Thread Tools
Old May 29, 2010, 06:48 AM   #1
johnspack
3500 Posts
 
Join Date: Oct 2007
Location: Nelson B.C. Canada
Posts: 3,730 (1.81/day)
Thanks: 283
Thanked 750 Times in 516 Posts

System Specs

Security for a digital sales server-hardware firewall?

I'm looking for industrial strength hardware protection for a server that will have digital downloads. If software methods could be employed, I'd be interested as well, but I'm sure I need hardware protection. The method of sales are being dealt with by other parties, my job is to recommend security for this T3 server, which is based on the east coast of the states, and I'm mainly responsible for running. I need to make a recommendation to the owner as soon as possible. I've looked at many hardware firewall solutions, the best of course being much too expensive. This has to be something easy to employ, as I'm a continent away, and can't be there to install it. The owner at this time does not have a lot of funds for this. Any ideas for this anyone? Go easy on me, I'm more hardware tech than IS guy, so some of this is a bit new, but I have to learn it....
__________________
Heatware: http://www.heatware.com/eval.php?id=73875
Clan !! The Fighting 24th !!
http://fxxiv.forumotion.ca/
Buy the games you like! Boycott the garbage!
Cruncher: P6T Xeon ES W3570 6Gbs Ram
1xgtx285 1xgtx260
johnspack is offline  
10 Million points folded for TPU
Reply With Quote
Old May 29, 2010, 12:20 PM   #2
Hybrid_theory
1000 Posts
 
Hybrid_theory's Avatar
 
Join Date: Mar 2007
Location: ontario canada
Posts: 1,691 (0.75/day)
Thanks: 113
Thanked 164 Times in 146 Posts

System Specs

You're doing sales, you need someone with knowledge to install it and configure it, you honestly cant get a good solution that a newbie can install.

The server itself needs to be hardened. If its running IIS or apache, make sure to follow guides for hardening those solutions, there are also several for windows server 2003/2008 and variants of Linux on how to harden them. You'll want to configure software firewalls properly, allow as little as you need to for the server to run. Install some anti virus, whether Linux or Windows. Linux has clam AV, for windows go with something commercial.

For a firewall, really depends what kind of traffic you're to expect. The Cisco ASA's for example can handle a lot of traffic in the higher models, like ISP amounts. So you could look at one of the lower models maybe, see if they're in price range. If not, DLink sells commercial firewalls for a reasonable price. As does Barracuda.

If this is a web server, you may want to place it in a DMZ on the firewall. But if it just interfaces with one, put it behind the firewall and your web server on the DMZ, and just allow communications between the two that are needed.
__________________
xboxlive: Hybrid461
PSN: ryan461
Steam name: Hybrid_theoryTPU.
Hybrid_theory is offline  
Reply With Quote
Old May 29, 2010, 12:25 PM   #3
IggSter
200 Posts
 
IggSter's Avatar
 
Join Date: Aug 2007
Location: BY-S36
Posts: 422 (0.20/day)
Thanks: 137
Thanked 120 Times in 102 Posts

System Specs

Have a look at Juniper for a firewall solution. They tend to be just as good as Cisco, a good bit cheaper and mostly managed and configured via a GUI.
__________________
IggSter is offline  
Reply With Quote
Old May 29, 2010, 12:26 PM   #4
W1zzard
Benevolent Dictator
 
W1zzard's Avatar
 
Join Date: May 2004
Location: Stuttgart, Germany
Posts: 13,792 (4.18/day)
Thanks: 184
Thanked 10,286 Times in 3,175 Posts
Send a message via ICQ to W1zzard Send a message via AIM to W1zzard Send a message via MSN to W1zzard

System Specs

are you looking for protection against intrusion? DOS? or simply to protect the downloads from unauthorized download ? how are you distributing the files? http? ftp?
do you need to protect a whole network or just a single machine?

Last edited by W1zzard; May 29, 2010 at 12:36 PM.
W1zzard is offline  
Reply With Quote
Old May 31, 2010, 08:55 AM   #5
johnspack
3500 Posts
 
Join Date: Oct 2007
Location: Nelson B.C. Canada
Posts: 3,730 (1.81/day)
Thanks: 283
Thanked 750 Times in 516 Posts

System Specs

Ug, I think I need to talk to the team more about this. Probably http download link with ssl enabled verisign link or similar. There's even talk about linking through GoDaddy. I don't know much about this yet, so I don't know what to recommend yet. I believe the server itself is on linux, and on some kind of secure rack, possibly with a linux firewall in front of it. It may get shifted to the windows server I manage however, and that worries me. I think intrusion is the least of my worries, but still a concern, I'm worried more about secure transactions of the product. I would only need to protect a single server for this. This may be a bit above our heads yet, but they insist on going ahead. So, any tips, yes please!
__________________
Heatware: http://www.heatware.com/eval.php?id=73875
Clan !! The Fighting 24th !!
http://fxxiv.forumotion.ca/
Buy the games you like! Boycott the garbage!
Cruncher: P6T Xeon ES W3570 6Gbs Ram
1xgtx285 1xgtx260
johnspack is offline  
10 Million points folded for TPU
Reply With Quote
Old May 31, 2010, 01:57 PM   #6
Hybrid_theory
1000 Posts
 
Hybrid_theory's Avatar
 
Join Date: Mar 2007
Location: ontario canada
Posts: 1,691 (0.75/day)
Thanks: 113
Thanked 164 Times in 146 Posts

System Specs

If it is indeed a webserver, IIS is actually more secure than apache. There's little configuration needed out of the box with it. And since it is used less than Apache, it is attacked less.
If you're worried about transactions across the web, ssl enabled verisign is a good way to go.
__________________
xboxlive: Hybrid461
PSN: ryan461
Steam name: Hybrid_theoryTPU.
Hybrid_theory is offline  
Reply With Quote
Old May 31, 2010, 10:18 PM   #7
Easy Rhino
Linux Advocate
 
Easy Rhino's Avatar
 
Join Date: Nov 2006
Posts: 10,226 (4.29/day)
Thanks: 1,207
Thanked 2,775 Times in 1,793 Posts

System Specs

secure transactions, aye? a lot of it depends on what billing company (if any) your organization goes through. a lot of times going with a third party billing company saves money and is more secure. transactions are done over SSL and on THEIR servers. you simply provide a link or some sort of form to make the transaction. i don't know of any specific software as these will be web based purchases i am guessing. after purchase, you can allow http or ftp downloads. personally, ftp is the way to go. every purchase should generate a unique ID and KEY that can be used to authorize the download. if you are worried about somebody being able to intrude on your network and download data without authorization make sure you have strict security settings. have at least 1 firewall in front of the host server. are you guys co-locating your servers? that would be the best bet if security is an issue. they tend to handle all of that and provide their clients with a best practice guide so you can understand how they operate and ways to keep all of your downloads secure.
Easy Rhino is online now  
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
PC security shield fails to deliver my product via digital after 3 days. D007 General Software 14 Mar 28, 2010 08:05 AM
[WTB][US] Old hardware mobo/cpu/ram <$30 for all. need server Damian^ Buy/Sell/Trade/Giveaway Forum 5 Sep 30, 2009 12:12 AM
[FS][US] Dom's Hardware Sales domy85 Buy/Sell/Trade/Giveaway Forum 18 Jul 16, 2009 12:30 PM
When will the hardware sales begin? Huxley2k7 General Hardware 9 Dec 19, 2007 11:22 PM
PS3 Sales Beat Wii Sales for Second Week in Japan zekrahminator News 11 Nov 25, 2007 08:31 AM


All times are GMT. The time now is 07:04 PM.


Powered by vBulletin® Version 3.8.6
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
no new posts