home news blogs forums events research newsletter whitepapers careers


Network Computing Network Computing Network Computing
HOT PICKS

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers


Security
C E N T E R F O L D  
Bell Canada Secures the Last Frontier

  July 9, 2001
  By Kelly Jackson Higgins


It's a hot spot for malicious code and viruses -- the oft-neglected, wide-open space where remote users travel on the Internet before they hit the secure corporate VPN (virtual private network). This is the initial ISP connection from home or on the road that carries remote users to the VPN, and where those users surf the Web for personal use.



Bell Canada is filling this security gap with personal firewalls, initially for 6,000 of its 22,000 remote workstations and eventually for all of them. "If you don't have protection on a machine before the VPN portal, you're exposed there," says Bill O'Brien, Bell Canada's senior advisor for corporate security.

If a telecommuter's laptop picks up a virus before hitting the secure VPN connection, for instance, it can unwittingly carry that virus to the VPN, O'Brien says. "In VPN mode, that virus propagates," he adds. "When the user plugs in behind the VPN firewall, he transports to the office all that has talked to his machine," including the tainted code.

Bell Canada runs InfoExpress' CyberArmor personal firewall software on the company-owned PCs and laptops it issues to its remote users. The application filters the traffic going in and out of the NIC and reports events to Bell Canada's CyberServer, which logs the events and threats, such as break-in attempts, into its database.

Things are airtight outside the VPN -- no FTP or file-sharing in open Internet mode. The personal firewalls allow only e-mail and VPN access, but there are exceptions for IT workers and other power users. "We close all but the required basic ports, but we evaluate any exceptions," O'Brien says. There is more freedom once you hit the VPN, he adds, but access privileges are based on policy.

The catch is determining just how much custom policy to invoke with the personal firewalls, especially for IT users who need access to more than e-mail and the VPN. "You have to decide how far to take it flexibilitywise -- you can be so flexible that you might as well throw the firewall out the window," O'Brien says.

Bell Canada needs to configure policy for different sets of users, including service providers, contractors and its own corporate users. Using the CyberArmor software, Bell Canada can give a service provider that maintains one of its servers access to that server over the VPN, for instance. The personal firewall recognizes that the VPN has been activated and loads the user-specific access permissions, O'Brien says. And the Nortel Contivity VPN switch controls where users go based on their group profiles, he adds.

The VPN firewall recognizes each user by his or her e-mail address when he or she hits the corporate edge. "Then we can determine what group the person is in and download the firewall profile," O'Brien says.

One catch with the CyberArmor personal firewall is that it is visible to the user. The firewall displays a pop-up window of a problem, for instance, warning the user and asking whether to continue. "It's up to the user to say 'yes' or 'no' here," O'Brien says. To prevent users from disabling the personal firewalls, Bell Canada is moving its remote machines from Microsoft Windows 95 and 98 (which let users disable the firewall function) to Windows 2000, which doesn't.

Next for Bell Canada is a PKI (public key infrastructure) that will complement the personal firewall system and the VPN infrastructure. Bell Canada is installing Entrust PKI software, using digital certificates for authenticating each machine and, eventually, for authenticating the users themselves. The digital IDs will help define the users' privileges.

For now, however, Bell Canada is still focusing on beefing up its remote-access security. "The personal firewall has allowed us to regain control of what employees are doing on the Internet," O'Brien says. "But we're still playing catch-up."







Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.










InformationWeek U.S. IT Salary Survey 2008
Salaries for business technology professionals are falling. Here's what you need to know in order to make good hiring decisions and personal career choices. Purchase Today: $299
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



techweb
Online Communities TechWebInformationWeekLight ReadingIntelligent EnterprisebMightyNetwork ComputingDark ReadingDigital LibraryWall Street & Technology
Byte & SwitchNo JitterInternet EvolutionLight Reading's Cable Digital NewsContentinopleUnStrungBank Systems & TechnologyAdvanced TradingInsurance & Technology
Face-to-Face Events
InteropWeb 2.0 ExpoWeb 2.0 SummitVoiceConBlack HatCSISoftwareEntrprise 2.0 ConferenceGTEC
Mobile Business Expo
InformationWeek 500 ConferenceBuy Side Trading XchangeBuy Side Trading SummitBank Executive SummitInsurance Executive SummitTelcoTVEthernet ExpoOptical Expo
Magazines  
InformationWeekWall Street & TechnologyInsurance & TechnologyBank Systems & TechnologyAdvanced TradingMSDNTechNetSmart EnterpriseThe Architecture JournalDatabase Magazine
 
Research & Analyst Services  
Heavy ReadingInformationWeek ReportsInformationWeek Analytics
 
   
   
App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |   Briefing Centers
Copyright © 2008  United Business Media LLC  |  Privacy Statement  |  Terms of Service  |  Your California Privacy Rights