techie_g33k Posted January 26, 2005 Report Share Posted January 26, 2005 I am working on a Windows 2003 server that will be running Plesk and be used to web hosting. I am looking to know if it is suggest to use the built-in firewall for Windows 2003 or to install a 3rd-party one? Also what is the best PC AV (we have a e-mail scanning AV already) to use on this kind of server?Thank you very much in advance! :D Quote Link to comment Share on other sites More sharing options...
scuzzman Posted January 26, 2005 Report Share Posted January 26, 2005 Do NOT use the Windows firewall. The one, at least in xp, sucks.If you're looking for a good firewall, might I suggest Zonealarm Free Edition and as for Antivirus, I use AVG, which is also free. As for paid AV, I would try to avoid Symantec and McAfee, as they re-write the WIN.COM and are a pain to uninstall. Take a look at TrendMicro.Also - Welcome to WF! Quote Link to comment Share on other sites More sharing options...
andsome Posted January 26, 2005 Report Share Posted January 26, 2005 You will get plenty of conflicting advice regarding Firewalls and AV programs. I definitely would not use the Windows Firewall, it is very lacking. I differ with several others on this forum, in that I have always used Norton AV and Firewall, and have always been very happy with both. I did once try McAfee, and uninstalled it very quickly.WELCOME to WF Quote Link to comment Share on other sites More sharing options...
techie_g33k Posted January 30, 2005 Author Report Share Posted January 30, 2005 Thanks for the Info. I never much trust the MS build-in stuff, but thought I'd ask.I have head a few good things about Trend Micro, though never have used them myself.I always thought BlackICE was a good firewall, but so far neither of you even mention it?I have had a lot of dealing with Norton AV/FW and have mixed feelings about it (speically with the way 2005 IS for Norton has been seent o freak out and block OE eve though it's allowed - but not worried much as it's a server w/ no need for OE to even run).Would love to hear some more input, and I am glad to be here :D Quote Link to comment Share on other sites More sharing options...
scuzzman Posted January 30, 2005 Report Share Posted January 30, 2005 BlackICE?You should really REALLY read this article...http://www.grc.com/dos/grcdos.htmBlackICE Defender v2.5 ($39.95) —I did not have a current copy of BlackICE Defender around, but I felt that this was an important test. So I laid out $39.95 through Network ICE's connection to the Digital River eCommerce retailer and purchased the latest version (v2.5) of BlackICE Defender hot off the Internet. I had already removed all traces of ZoneAlarm and restarted the machine, so I installed BlackICE Defender, let everything settle down, and restarted the machine with my packet sniffer running on an adjacent PC.As far as I could tell, BlackICE Defender had ABSOLUTELY NO EFFECT WHATSOEVER on the dialogs being held by the Zombies and Trojans running inside the poor "Sitting Duck" laptop. I knew that BlackICE Defender was a lame personal firewall, but this even surprised me.The Zombie/Bot happily connected without a hitch to its IRC chat server to await further instructions. The Sub7 Trojan sent off its eMail containing the machine's IP and the port where it was listening. Then it connected and logged itself into the Sub7 IRC server, repeating the disclosure of the machine's IP address and awaiting port number. No alerts were raised, nothing was flashing in the system tray. The Trojans were not hampered and I received no indication that anything wrong or dangerous was going on.I took a lot of grief after my LeakTest utility cut right through BlackICE Defender. Network ICE told everyone that LeakTest was "being allowed through" because it was a completely benign Trojan. I knew that was a load of bull (and they must have too), but it didn't really matter to me, and I had no affirmative means of proving otherwise.Well . . . I have that now, and so do you.I performed one final test: As I had with ZoneAlarm, I attempted to connect to the Sub7Server Trojan running inside the "Sitting Duck" machine on the IP and listening port number the Trojan was advertising all over the Internet . . . and it worked perfectly. I received Sub7's "PWD" prompt asking me to login.Anyone want an "only used once"copy of BlackICE Defender?I certainly have no use for it. Quote Link to comment Share on other sites More sharing options...
techie_g33k Posted February 27, 2005 Author Report Share Posted February 27, 2005 Well I have decided on using ClamAV for Windows (http://www.clamwin.com) and so far it has done well, though the true test will be in production use, as right now I have only 1 client testing it.Still unsure about Firewall, so holding back on pushing out to production until then.Please any other input would be GREAT! Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.