|
The increased reliance upon Internet services
unfortunately runs hand in hand with increased security
threats, failing to protect your dedicated server or
colocated server is something all companies should try
to avoid - we help with our managed firewall service.
Your dedicated servers or colocated servers sit behind
our hardware firewalls - multiple redundant firewalls in
failover mode - we configure and manage the firewalls to
fit with the requirements of your servers.
Some benefits of using our
Managed Hardware Firewall:
-
Packets
processed before they reach your server Before
the packets even come into contact with your physical
dedicated server or colocated server, they are
processed. Bad packets can't affect your server.
-
Packets
processed on dedicated hardware This leaves the
resources on your dedicated server or colocated
server free to carry out
its own role.
-
Packets
processed on redundant firewalls
We use multiple hardware firewalls, mirrored and in
failover mode, should one require a major software
update or fail for whatever reason, the other takes
over automatically.
-
Economical
We've made the expense of setting up a highly
reliable and redundant service, no need to setup
your own expensive hardware with our great value service.
-
Managed
We manage the firewalls, we'll work with you to get
a rule set in plain English from you - then configure
the firewalls rules. You don't need to know the
complexities of how to configure a firewall, just
tell us what you need in plain English.
A small example firewall configuration
for a dedicated server:
- Always block everything coming from
these bad IPs:
222.222.222.222 (BAD IP) 333.333.333.333 (BAD IP)
- Allow these ports to be accessed by
anyone from anywhere:
21 (FTP) 25 (email) 80 (web) 110 (email)
- Allow these ports to be
accessed only from our office IP address:
22 (ssh remote management) 123.123.123.123 (office IP)
- Block all other
traffic that doesn't match above
rules.
|
This rule set is a very simple 4 rule example of how
your dedicated server can be protected. When a packet enters
the network, before it reaches your server it runs
through one of the firewalls. Packets destined for
your server will flow through the rules we have
devised for you.
In the above case you have a bad IP
list, which enables you to explicitly deny access
from certain IPs to your server. Great if you have
someone trying to flood your server with requests
(dos attack).
Then you specifically allow access to
services which your provide (web pages, email, and
FTP) to everyone apart from those on your bad list.
Your remote management ports which you use to administer your dedicated server is locked down to
only your office IP address - thus stopping bad
users even attempting to crack your password as they
wont even be able to connect.
Then block any
remaining traffic which hasn't matched a rule so far.
This is a bog standard basic example of a rule set
which could be used - we will work with you to
create the rules you require.
Our hardware firewall can help to protect
against:
-
IP
Spoofing Blocking hackers who are using forged
(spoofed) IP addresses to attempt to attack or hack
into your dedicated or colocated server.
-
Denial of Service
(DOS) Attacks A malicious user may be trying
to flood your server with requests, brute force
(repeatedly attempt to hack) passwords of email,
ftp, and other services.
-
Exploitable Port
Ranges Locking down ports your dedicated or
colocated servers can use, thus preventing hackers
attempting to connect to malicious software or
vulnerable software.
-
MSSQL and MySQL
Remote Exploitation Locking MySQL and MSSQL
database's down so only specific IP Addresses can
access them remotely.
-
Remote
Administration Tools Servers need to be
remotely managed, by specifying the IP addresses
that can access the management software adds another
layer of protection to your dedicated server or
colocated server even before a password prompt is
given.
You can purchase the Managed Hardware Firewall
service for your dedicated server or colocated
server using the online order system when
configuring your dedicated server or colocation
order. |