We hope to share with you our thoughts on IT topics and issues encountered by businesses in the Bay Area.
Please feel free to contact us at 408-228-4488 or sales@netcal.com if you would like a quote for IT Support Services or a particular IT Solution.
I know there are many websites that lists a bunch of features of Microsoft’s latest Windows Server 2008. I also know that these lists sometimes forget the fact that technology in the workplace is only as good as the business value benefited from it. I understand that during these tough economic times, migrating and upgrading your systems to Windows Server 2008 will be an option that is heavily scrutinized. Hopefully, this blog entry will help you create an informed decision for your business.
Below are the features that stand out to me when deploying Windows Server 2008. I will try to explain how these features can translate to a more secure, efficient, and stable network.
Active Directory
OS Enhancements
You see and hear the buzz word swarming around the internet of networks with special setups that tout “High Availability” or sometimes commonly known as “H.A.”. What is it? What does it do for my business? Ultimately in today’s economic climate… Can I afford not to have it?
There are actually different types of HA that you can implement into you IT infrastructure. At its core, HA is a system designed implementation that ensures a certain absolute degree of operational continuity during a given measurement period. In simple business terms, HA makes sure your employees are able to continue working even if primary service providers or servers or your local network experiences some sort of an outage. Yikes!
As an example:
For small to medium sized business, you need a solution – High Availability.
Most administrators of small to medium sized networks are probably already assuming you need twice the amount of hardware, extra connectors, licenses, and more. Depending on the current network equipment you have, High Availability to a certain degree can very easily be a viable option.Lets take a very common scenario as a prime example of what High Availability can do.
Your Users: You have a user base of 30 people. All with varying job tasks which rely heavily on internet access to go about those tasks.
Your Network: Your have DSL service from your local ISP. You have a Cisco router/firewall, medium grade switch, a file server and a Directory server, and a few occasional remote VPN users.
The Outage: Your internet is somehow disconnected or cut off! Covad can’t help until they send a 1st level support tech to check their field equipment, someone between 12pm-6pm. And this may not even be a field equipment problem.
- you have 30 people grumbling they can’t get work done.
- you have 30 people grumbling they can’t access your online company email.
- you have 30 people standing around the water cooler.
- you have the CEO at a remote location unable to access the internal company files.
- your travelling remote sales associate can’t make the sale because they can’t VPN to access the internal company sales files.
- you’re at the mercy of your local ISP’s support to fix the problem in a timely manner.
With a very simple High Availability setup, you could be saved. This is a very common and possible situation and a High Availability setup may alleviate the frustration, anger, and the ever possible firing of office employee’s.By choosing a business level Cisco router, you get the benefit of a very customizable and upgradeable platform. You may think the price for Cisco equipment is high, but their products are truly made for business. You would never want to trust “home” equipment to run your core business infrastructure do you (this is another topic)?
The Answer: To avert a potential disaster, you have a very short shopping list. All you would need to implement a “High Availability – Dual ISP – Redundant internet connection – Redundant VPN” office network is a specific Cisco hardware module aka “WIC” module, a secondary DSL internet provider (other than your primary -Covad), and a few minutes during office downtime to get it all installed and configured. Total hardware cost can easily be had for under $300, and total monthly cost for a secondary DSL line might be $25 (shop around). If you didn’t have a High Availability setup, you may have lost MORE due to the office down. Lost employee production, lost sales, lost clients, lost trust, and who knows… a Lost Job.
“The Outage” has been avoided. Your High Availability Cisco router setup automatically switched over to the secondary ISP, and you were alerted of the switch over. Your employee’s continue along with their tasks, and may not have even noticed the internet disruption.
And because you were alerted of the ISP failover, you can easily send out a “Daily Tech Update” to your remote and C-level staff, letting them know to use the secondary Cisco VPN profile or to call you for assistance.
Today, it’s all about security. If you aren’t practicing good security, you are probably going to be held accountable for the information that sneaks into your network, and especially the information that can find its way out of your network.
Script kids and hackers alike all begin their first “hacking” by targeting what’s easy – The poor, unsuspecting FTP server. All day long, doing its job of blindly sharing and accepting files. Here are the four key parts of FTP (and its cousin Telnet) that make it insecure.
So you have your brand new shiny server with tons of disk capacity, and a clean install of Windows 2008 Server. You’re tasked with setting up the new company FTP site. If you have experience with setting up IIS and FTP services on Windows 2000/2003 server, then you know exactly how easy it is to setup FTP service. With Windows 2008 server, securing your FTP server became just as easy. And the benefits, immense!
Windows 2008 Server utilizes the method FTPES aka FTP Explicit mode. In explicit mode, an FTPS (FTP Secure) client must “explicitly request” security from an FTPS server and then step-up to a mutually agreed encryption method (usually the minimums are defined on the server). It currently isn’t packaged onto the Windows 2008 server install media, but information and the download can be found here http://www.iis.net/downloads/default.aspx?tabid=34&g=6&i=1619
Without this extra handshaking and communication, your server-to-FTP client communication is susceptible to snooping and hijacking. With these simple steps, your server avoids the pitfalls listed above, that plague many FTP servers out on the web.
Securing your new Windows 2008 based FTP server comes down to these steps:
Tada, you’re done! Now your Windows 2008 FTP server is protected. From beginning to end, Connection, Authentication, Authorization, Data Request, Data transfer. It’s all encrypted.