Showing posts with label firewall. Show all posts
Showing posts with label firewall. Show all posts

Wednesday, September 11, 2019

You Need a Black Cloud Software Defined Perimeter

By: John Shepler

Secure your network with black cloud SoftwareAre you a trusting person? Too bad. That’s going to get you hacked. Respect and privacy are admirable things, but they are not guaranteed by today’s Internet. In addition to all the incredible employees, partners, suppliers and customers that you hold in high regard, there is a dark underbelly of professional criminals, hobbyist & mercenary hackers, mischief makers, psychotics, and nation states with agendas all trolling the same network. Some are looking for victims of opportunity. Others have you in mind as a target. Can your firewall and VPN fend them off?

The Virtual Hopefully Private Network Connection
The VPN or Virtual Private Network was designed to make the Internet act more like a private line or MPLS (Multi-Protocol Label Switching) network. Even if you have a T1, DS3, OC3 or Ethernet private line at the office, you have a big security hole when an employee out on a sales or repair call stops by the coffee shop and connects back using the free Wi-Fi provided by the store.

Free really means free and open. That guy in the corner staring at his laptop is watching your traffic. He either hacked the shop’s WiFi or created his own look-alike “free” WiFi network that you connected to instead of the real one. This is called “man in the middle” and it is what VPN was designed to protect against. The VPN creates an encrypted connection called a “tunnel” from your employee’s computer to your office server. That makes it pretty hard for someone to get in the middle of the conversation unless they have the private key… and they don’t.

VPN Weaknesses
Not all VPNs have a rugged 256 bit military-grade encryption. Some use protocols that are relatively easy to crack with available hacker tools. PPTP (Peer to Peer tunneling Protocol) is over 20 years old and is desirable because it is fast and easy to setup and use. It’s also more vulnerable than protocols with stronger encryption.

Not all VPN vendors are equally capable. Weak ones may have back doors in their servers or other weaknesses that make it easy to hack the VPN server in the cloud and get everybody’s data. You won’t know until you are hacked and can’t figure out how.

An overall weakness of VPN is that it just protects the tunnel into your company. If that is compromised one way or the other, your entire network and everything on it is wide open to explore and perhaps attack. it would be better if only a small part of the company assets were exposed instead of everything all at once.

The Software Defined Perimeter Black Cloud
The idea behind a Software Defined Perimeter (SDP) is that trust is minimized by allowing access to resources user by user on a need to know basis. The research was done by the U.S. Department Information Systems Agency (DISA) and has come to be known as a “Black Cloud.” The black designation means that the network infrastructure is hidden within the cloud. There are no visible DNS or IP addresses.

SDP authenticates each user and only gives them access to the resources you have approved for that particular user so they can do their jobs. The user or IoT device has no idea what else is on the network. They can’t see it. If they can’t see it, they can’t get access. Someone impersonating that user can’t either.

A system of SDP Hosts and Controllers communicate and verify the authorizations. The Controller has the job of connecting the Initiating and Accepting Host data channels through a Gateway, once authentication and authorization has been completed through the control channels.

The SDP is not only between clients and the data center. It is also deployed within the data center to partition the network to isolate high-value applications. Only a limited number of users with have access to the highly protected application or even know it exists.

Encryption and cloaking are key to SDP security. The usual network probing, such as port scanning, won’t work because nothing will show up in the scan. In a way, SDP is creating virtual networks on a user by user, session by session, basis. What goes on behind the curtain is a complete mystery.

The End of Networks As We Know Them?
The TCP/IP network that has served us so well for decades has to go underground to keep its relevance in today’s high threat environment. We can no longer do business without the Internet and there are just too many bad actors on the public Internet. Technology must evolve to provide the illusion of a simple open Internet but with none of the familiar network topology visible.

Has your company network been hacked or are you concerned about the business disruption this might cause? Right now would be a good time to see what advances have been made in network security, especially managed security solutions in the cloud.

Click to check pricing and features or get support from a Telarus product specialist.



Follow Telexplainer on Twitter

Wednesday, May 17, 2017

How Your Network Provider Can Help Keep You Secure

By: John Shepler

It seems like every week there’s a major “hack attack” against companies large and small. Once upon a time, this was more of an annoying curiosity than a serious problem, as the intruders were mostly curiosity seekers looking to enhance their tech cred within their computer enthusiast community. Now it’s serious trouble. Today’s attacks are at least disruptive to the conduct of business and at most create unrecoverable destruction.

Have You Covered ALL The Bases?
You’ve tried to adhere to recommended practice, but there’s always that nagging feeling that you’re still vulnerable. Is there anything else within reason that can be done to keep the bad guys out? Let’s take a quick look at some Cybersecurity Basics, courtesy of Level 3 Communications, a major network service provider:


You are probably already implementing software patch updates, strong passwords, anti-virus software, and Internet firewalls as technical solutions. Employee training to avoid things like clicking on email links is also excellent practice.

Where The Network Provider Fits In
Even so, as shown in the video, there are protections that your network service provider can implement to stop these attacks before they even get to you. Certainly, the service provider can monitor their own core servers and mitigate attacks, such as Distributed Denial of Service (DDoS) that try to traverse their network connections. But, a managed service provider can also extend that level of monitoring and protection into your network as well.

The Team Approach
Why go it alone, when you can have high reliability wide area networking services along with full-time security monitoring and attack protection working on your behalf behind the scenes. Seems like there is no such thing as too much security these days, so this could be a great time to consider adding managed network security to the protections you have already established… just to be sure.

Your Options
Are you interested in higher performance connectivity with the advantages of monitoring and added network security? Find out about the wide range of networking options available to you now.

Click to check pricing and features or get support from a Telarus product specialist.



Follow Telexplainer on Twitter

Monday, December 14, 2015

The Ultimate Wireless Firewall: Networks That Don’t Connect

By: John Shepler

Network security has become a major concern of any business that connects to the Internet. There’s hardly a day goes by that we don’t seen another announcement of a company that has been breached. We may be seeing only the tip of that iceberg. The public reports tend to be about companies that have their customer information compromised, especially credit card numbers. Other businesses might discover intrusions that don’t affect their customers and may elect to remain mum simply to avoid the embarrassment and bad press.

Secure your network before anyone breaks in.Who Can Afford Cyber Security?
The result of all this hacking and cyber warfare is that IT departments have gone on high alert. If they are going to stay connected on the Internet, they have no choice but to pay up for security appliances and cloud based network security. But what about small and medium size businesses? Can your typical doctor’s office or restaurant really afford to pay for cyber defense?

Common Sense Measures
Certainly, any independent professional or small business can take the basic common sense steps to keep casual snoops and hackers scanning for low hanging fruit out of their networks. Nearly every router also includes a firewall function and encryption for Wi-Fi access. Anyone who neglects to change the default login and password and enable the highest level of encryption their equipment will handle, is just too naieve for words.

Public Access Is Always Vulnerable
Even so, there are still those lingering doubts that the network is protected. When you unlock Wi-Fi access so that customers can use your hotspot, you run two risks. First, you open a vulnerability. The vast majority of your customers will only use the broadband access as a convenience. They’re not out to cause you trouble. But… there are characters with malicious software on their laptops who can sit themselves down and troll other customers or try to break into your network. Wi-Fi doesn’t stop at the door these days, so they may be parked outside or even sitting a block away.

Wired Only?
The safest solution is to only use wired access inside the business and avoid Wi-Fi altogether. That may really limit you and your employees by ruling out any portable and mobile devices. The next step up is to have a Wi-Fi router but lock it for employee use only. That leaves customers and guests frustrated, since they’d like to use their tablets while waiting.

Will a Firewall Work?
Is it sufficient to simply install a firewall between your business network and your public-facing Wi-Fi hotspot? The idea makes a lot of business owners nervous. It’s hard to tell, especially when you don’t have a full-time IT department watching everything, whether you are truly protected or not. Consequently, they opt for either locking down their wireless network or not having one at all.

The Two Network Solution
Here’s another approach. Install TWO networks instead of one. The first is your internal business network. This can be high performance Ethernet over Copper or Fiber Optic WAN bandwidth. It might not even connect to the Internet. Either way, connect only your own equipment to this network. If you have wireless access, lock it down. Then order a second Internet connection. This one is for your customers and does not need the performance characteristics of your primary network. A good choice for many small and medium businesses who deal with the public is cable broadband, just like they have at home.

Why Cable Broadband?
The beauty of cable broadband is that it is inexpensive, even for business locations. You get decent bandwidth levels of 10 to 100 Mbps and it's pretty reliable these days. There’s a bonus for businesses with customer waiting areas. You can bundle cable TV service with your broadband for little extra cost. You may want the TV service anyway. Why not add Internet broadband as an extra convenience?

Keep 'em Apart
Here’s what you don’t do. You NEVER connect your business network with your customer network. They remain completely separate. If you get them from different providers and keep the wires apart, there is no chance of an interconnection. If someone sits outside at night and steals your broadband signal or tries to break into the public wireless network, they won’t get far. It doesn't really connect to anything other than the Internet.

What About Your Primary Internet Access?
Most organizations do need some type of Internet access to acquire information, place orders and connect with their customers. If your main business network is not strictly internal to your company, you still need network security between your LAN and the Internet. If you have the expertise on-board, you may be able to install and manage your own firewalls. Most smaller and medium size companies will find it more cost effective to order managed security in the cloud. WAN bandwidth providers who offer this option have the necessary expertise in-house and available 24/7.

For Emergencies Only
I know. There’s a temptation to use that second network for business purposes if your primary network runs out of capacity or suffers an outage. Be very careful. In such an emergency, you may wish to disconnect the public Wi-Fi hotspot or lock it to prevent any but employee access.

Do you need point to point WAN bandwidth, primary dedicated Internet access or separate customer-facing hotspot bandwidth? How about managed security for your company? If so, find out what secure network solutions are available and appropriate for your size business.

Click to check pricing and features or get support from a Telarus product specialist.



Follow Telexplainer on Twitter

Monday, November 25, 2013

Here’s Why Companies Actually Want BYOD

By: John Shepler

Do you wince when someone brings up the topic of BYOD or Bring Your Own Device? It can be more than an ulcer producer for IT managers. The whole company’s intellectual property can be put at risk by employees blissfully aware of the threats. They bring in what they want and connect it to the company network. Your carefully planned security protocols go out the window. What to do?

Get control of BYOD and save money at the same time.Most companies have drawn a clear line between what belongs to the company and what belongs to the individual. Unable to manage the wild and wooly world of consumer electronics configurations, they simply lay down the law and say you can’t use your personal phone, laptop or tablet for company business. But since you clearly need technology to do your job, something has to give. In frustration, the company issues you a corporate smartphone, laptop or tablet that are only used for business. Does that put the issue to rest?

Oh, not really. Smaller companies can’t afford to pony up the capital to hand out gadgets to everyone who needs or wants them. They may simply wince and take their chances that nothing will go horribly wrong. Larger operations install firewalls and other means to protect key information and hope they will be a bulwark against data going out and intruders coming in. Meanwhile, employees continue to casually use their own equipment, both inside and outside the company, for business activities.

Why? Partly because it’s more convenient. Also because everybody likes what they’ve customized for their own use. They don’t want to be carrying two copies of everything and switching back and forth. They don’t want to have to mentally jog between different hardware and different operating systems. It’s just not human nature.

Is there anyway to bridge this gulf and make everybody happy? One answer may be found in the new XO WorkTime service. It’s a cloud based UC (Unified Communications) application that integrates your company’s communications systems with employee smartphones and laptops. In effect, the personal devices become access devices to the same resources provided within the corporate walls.

So, here’s why you actually want BYOD… as long as you keep it under your control with an app like XO WorkTime. The first big advantage is capital investment. Why should you as a company manager spend thousands or millions of dollars to build and manage a pool of equipment when your employees will do that for you at their expense. You don’t have to buy them a smartphone because they’ve already bought their own iPhone or Android smartphone.

The next big advantage is happier employees. You’re no longer on their case about turning off their personal gadgets inside the company. Less nagging, less spying, less scolding and everybody’s in a better mood. It gets even better when employees realize that they have their desk phones on their personal phones. They can roam at will and be connected with other employees and customers effortlessly.

Here’s how this works. Your company needs to be using XO’s VoIP service internally. These include IP Flex, IP Flex with VPN, SIP, Enterprise SIP and Hosted PBX services. You simply install the XO WorkTime application on every device that needs it. At that point employee devices have a dual personality. They are work phones and they are personal phones.

The personal side remains unchanged. Personal apps and information are the same as they were. They also remain outside of the company side of the WorkTime app. What happens on the personal side stays on the personal side.

What happens on the business side also stays on the business side. You can safely transport business communications using encryption and VPN tunneling. Your company applications stay in a secure, password protected environment.

Employees have their business calling plan and office number while they are in WorkTime mode. They’ll use the same calling features they use in the office from the WorkTime applications while on the go. That includes features such as simultaneous ring on desk, smartphone or home computer plus presence, IM and video. On-net, local and inbound calls are free. Long distance calls are included in the company plan and don’t count against your personal minutes.

Are you frustrated with the cost and security problems related to enabling mobile business communications? Get expert consulting to learn more about how XO WorkTime and other sophisticated hosted VoIP services can work to your advantage.

Click to check pricing and features or get support from a Telarus product specialist.



Follow Telexplainer on Twitter

Monday, December 19, 2011

Cyber Security Threat Protection In the Cloud

In days of yore, when castles were in vogue, the nobles found that massive stone fortifications were not enough to secure them from determined invaders. What they did was to ring the castle grounds with a deep water-filled ditch called a moat. This effectively prevented sieges from battering rams and tunneling under the castle walls. The lesson here is that your infrastructure is much easier to defend if you don’t let the bad guys anywhere near the main line of defense.

Get network security as robust as this castle and moat...Now let’s fast-forward to the 21st century and see how these medieval lessons-learned can protect our networks. Our massive stone castle wall is now a firewall. It’s effective in preventing most penetrations into the network. Like real stone fortifications and wooden gates, that firewall can only hold out so long against massive assaults at the network edge. What we need is a modern day moat. This is an electronic moat, of course, and it needs to surround our network but not be in it. Where can we get that layer of protection? How about in the cloud?

The cloud might just be the perfect first line of defense for local networks. It’s an idea that makes so much sense that MegaPath, a major networking service provider, is taking exactly that approach in a solution they call Unified Threat Management (UTM). This suite of managed security services can be implemented completely in the cloud, completely on-site or within a hybrid private/public configuration.

MegaPath’s UTM suite is offered in the form of Security as a Service (SaaS). It’s a multilayer approach that can easily fend off unsophisticated attempted break-ins and stand up to higher threat blended attacks. This suite also coordinates security alerting, logging, reporting, compliance and response.

What’s in the SaaS suite? It starts with an advanced firewall that features deep packet inspection with up to 500 firewall policies. Intrusion prevention features multi-layered and blended attack detection that handles both known and unknown threats. A powerful anomaly detector identifies and stops zero-day threats to all network types, including wireless.

No good network security system would be without anti-virus and anti-malware these days. This one has both signature and rules based blocking. Anti-spam deals with the onslaught of unwanted messages and deletes or simply tags them depending on your policy. There’s nothing like having to work your way through hundreds or thousands of spam messages each day to kill employee productivity.

Speaking of productivity, just what are all those employees browsing on the Internet anyway? Make sure their time is spent on company sanctioned activities with white and black lists and policy-based content filtering. Web application control goes a step further to give you precise control of apps like IM, chat, and voice or video on social media sites.

You’ll have data loss prevention with real time detection and prevention of your sensitive company data being transferred outside the company. That includes credit card, healthcare or financial data that is literally worth its weight in gold. Vulnerability scanning checks internal and external IP addresses to find and fix vulnerabilities in real time. Quarterly scans are implemented for PCI compliance. File integrity monitoring watches for unauthorized access or changes to critical system or configuration files.

Managed logging and security information management round out the MegaPath SaaS suite. These collect data and provide the alerting, reporting and archival you need for proper management. Portal based workflow management and tracking demonstrates due diligence in meeting organizational security policies and compliance reporting.

Are you feeling a bit vulnerable with the limited firewall and virus protection you have now? Sadly, the cost of one major breaking can far exceed the amount you’d spend preventing it with an effective cyber security solution. Now would be an excellent to investigate managed security services from MegaPath and other top tier network service providers.

Click to check pricing and features or get support from a Telarus product specialist.


Note: Photo of medieval castle and moat courtesy of Christophe.Finot on Wikimedia Commons.



Follow Telexplainer on Twitter

Tuesday, August 03, 2010

Windstream’s Enterprise Level Managed Security

The larger your organization, the more important network security becomes. You have more assets to protect, there are more nodes where something hostile can enter, the consequences affect more users, and you may be under stricter scrutiny from regulating agencies. Examples are HIPAA in the medical field and PCI DSS for financial transactions.

Managed security can keep intruders out of your network cost effectively.The simplistic firewall solutions that work fine for individuals, small organizations and even some medium size companies are just not sized for organizations with hundreds or thousands of users. They may not be robust enough to meet the threats, either. While some large organizations build an in-house security staff and effectively manage their own network security, others are finding that buying a managed security service is more cost effective.

Managed security for large and enterprise level organizations is a specialty of Windstream. Known as a provider of broadband Internet, phone services and digital television with millions of customers in 23 states, Windstream Communications also offers a wide range of IP-based voice and data services to business and government agencies. They’ve got the scale and expertise to meet the expectations of larger companies. Their newly expanded managed security service for enterprise businesses is well worth a look if your operation has outgrown its network security solution or if you are considering options to cut expenses.

Windstream’s security solution is fully managed and monitored around the clock. They’ve partnered with Fortinet, an acknowledged leader in unified threat management, to offer a highly robust security service. Since Windstream can now provide both the WAN bandwidth and security, they are in a prime position to be able to protect your organization from network intruders.

What do you get with Windstream managed network security? It’s a suite of service that include firewalls, antivirus protection and intrusion detection. Application intelligence detects and prevents malicious traffic gaining network access. You’ll have protection against the nearly continuous onslaught of viruses, worms and phishing attacks that are a fact of life with computer networking. Site to site Virtual Private Network (VPN) connections are IPSec encrypted. Remote access VPN and remote desktop options are available. Secure WiFi options are also available, as more and more companies are including wireless access points. Web content filtering is also included to protect employees from objectionable Web content.

Do you have a need to meet or exceed industry compliance standards such as HIPAA and PCI DSS? Windstream has a managed solution that will ease the burden of this.

If your organization has a need for large scale and robust network security and you like to let an expert service provider hand this for you, or you just want to see if managed security makes more economic sense than doing it in-house, then you should take a few minutes to put in a request for pricing and consultation from our Telarus consultants. It costs you nothing and could be a big money saver as well as offering peace of mind.

Click to check pricing and features or get support from a Telarus product specialist.




Follow Telexplainer on Twitter