Slashdot Mirror


Securing Your Internal Network from Windows?

acacord asks: "I am the Network Admin for a medium-sized law firm (hold the flames, please). We are one of the few Macintosh-based firms left. All of our workstations (near 150) will have been migrated to Mac OS X 10.2.2 by the end of the year. We have a couple users who think that they know more than the IT department and therefore insist that they maintain WinXP boxes on their desks. How should I configure a segment of my network for them, and them only, to make sure that the remainder of my networks are not susceptible to any of their natural security 'features' . Any and all ideas are welcome."

4 of 78 comments (clear)

  1. What threat? by steve.m · · Score: 4, Insightful

    What threat does a couple of XP boxes pose to 150 MacOSX boxes?

    Is there a known trojan/worm/virus that infects XP and then attacks MacOSX ?

    Could this entire story be blatant MS bashing, because it's a slow news day?

  2. Stay honest here and stop the reflexive M$ bash! by TeeWee · · Score: 4, Insightful

    Imagine a story where the opposite is true: a Windows Network Admin who asks how to secure a few Macs from the rest of the Win network. Be honest, the bloke would be flamed to a cinder, and rightly so, because securing a network should be part of a Network Admin's daily job!

    So why is the majority of the reactions like, "Oh, poor Mac Network Admin, those Win users deserve any shit they get!" Why not subtly reminding him what the fsck his job is in the first place?

    Oh wait, I see: he needs to maintain a few WinXP boxes in a *nix environ, so when he bitches he must be right. Because it's Microsoft. Right?

  3. Either you "own" your network or you don't by unsinkableme · · Score: 4, Insightful

    In the past, I have handled this question in a number of ways. First, you need to establish how necessary it is to their jobs to work on a platform different from the rest of the company. This doesn't have to be a platform war. There are plenty of reasons for them to want a different platform, pick your battles carefully. If it is still necessary that the Windows boxes remain, establish who the admins are for the boxes. If your endusers insist they can administer the boxes,I would refuse to allow them to attach it to the network. It's all very well and good for them to be technically savvy, but the network is still your responsiblity.

    However if you administer the machine, and I realize it's probably not your first choice, you need to start reading up on Windows. Yes, there's a lot to keep up with, however their can be some advantages to understanding different platforms and being able to administer and secure them in the same environment. And regardless of how any one feels about it, Window is still the most common business environment.

    Additionally, I see several post that seem to question the legitimacy of the original question. This *is* a legitimate question, as any one who has had samba and appletalk on the same network can tell you. Discussing security concerns when integrating two very different platforms with different vulnerabilities is more than reasonable for any Administrator, especially in a small business environment where the only other "collegues" they may have access to are the very same users insisting on the installing their own boxes.

  4. Meet Them on Their Own Terms by TheWanderingHermit · · Score: 5, Insightful

    They're lawyers, right? Don't deal with them as tech wannabes. Deal with them as lawyers. For a change like this, one of the very top PHBs must have either okay'ed this, or instigated it. Go up the ladder to the highest lawyer in the firm that was behind this switch. Have him help you prepare a form that says something like, "Since Windows XP has been shown to have the following security vulnerabilities...yada yada yada...and the Macintosh OSX has been shown to be a more secure system...yada yada yada...I understand that in insisting that I use Windows XP as my desktop operating system, I am increasing the risk of having not only my computer, but the entire corporate network either infected or damaged by viral programs, as well as the risk of my computer or the entire network being accessed illegally by unauthorized persons. I fully understand it is my choice to use this software and I take full legal and financial responsibility for any damage done to my desktop system or the company network as a result of my choice of running an OS with these known high risks."

    Be sure to include in the paper (where the first set of yadas is) lists of vulnerabilities of WinXP, including the recend IE/Outlook flaws for which there is (as of yet) no sure fix. In place of the 2nd set of yadas, put in documentation that shows OSX is more stable and less vulnerable.

    The point is to take the issue to them on their grounds and show them that their choice can have serious implications for them and the entire law firm and that they could be the idiot responsible for the whole system going down. If they are talked to in their language and made to see their choice as a real action with real (and possibly disasterous) consequences, it could open their eyes. You might still have to deal with WInXP, but it'll certainly get them thinking about it.