Secure LAN design:
Redesigning an entire site or LAN to have a level of security that matches the LAN's function is not a matter of
throwing a commercial firewall at it and walking away, as some people (think of them as firewall software resellers)
would have you believe.
It requires an honest evaluation of the existing state of the LAN, determination of whether certain kinds of machines
should be replaced with more controllable platforms, and usually a number of changes, additions, and safeguards,
only one of which may be an internet-facing "firewall".
Furthermore, a large number of secure LAN redesigns can, and in my opinion, should, be done with free, open-source
software. This is another thing that firewall software resellers would prefer you not believe because, obviously,
they make money through selling, and they may come up with a number of bogus yet legitimate-sounding aarguments
against this position.
The real-world track record of open-source software shows that correctly-managed, open-source software translates
into decreased vulnerability.
"Security through obscurity" is a phrase that rhymes, nothing more.
1USA's Computer Security Services can design and implement network security redesigns on some, but not all, sites.
We work with sites that are not overwhelmingly Microsoft dependent, or are willing to migrate to a linux platform
for their mission-critical servers. Microsoft workstations are normally not a problem, when treated correctly.
Because of the time-consuming nature of this kind of job, we are only able to do this for small to medium sized
service providers and businesses right now.