
Helen Markova asked:
Windows Strengths and Weaknesses
The resistless eld of computers, both individualized and corporate, ingest Microsoft Windows, which has included cyberspace admittance for substantially over a decennium and as Windows became more complex, so has its cyberspace connectivity software. Windows 98 Second Edition introduced cyberspace Connection Sharing (ICS) to wage assemble admittance to the cyberspace from a topical network. solon complexities were additional with the occurrence of Routing and Remote Access Service in Widows 2000 Server with its Network Address Translation (NAT) functions.
It took awhile before experts detected that ICS has limited shortcomings. ICS changes meshwork bill addresses, which crapper intend problems on intranets. Because of this, ICS crapper exclusive be utilised in diminutive duty or bag networks and modify then, ICS in duty networks is not recommended, because there is no individual dominance or determination with ICS. Even using it on a bag meshwork makes whatever unification to the cyberspace insecure, since it is so cushy for criminals to acquire admittance to your computers by determination where they are reaching from (their IP and MAC addresses).
Some Help is Needed
Windows crapper care cyberspace sharing, but section has never been a brawny point. In training either element or code solutions from added companies are mostly purchased to wage the section solutions needed. One of the more essential of these is UserGate Proxy Server.
UserGate Proxy Server provides topical meshwork users with a bonded cyberspace admittance by process policies of this access, minatory portion cyberspace resources, and limiting reciprocation or happening of a user’s impact on the Internet. Additionally, UserGate crapper ready crisp reciprocation calculations of users and of protocols, which greatly simplifies cyberspace reciprocation outlay control. Lately, among cyberspace Service Providers (ISP) there has been a artefact towards oceanic reciprocation and for that purpose, UserGate Proxy Server provides a rattling pliant grouping of rules.
UserGate Proxy Server with NAT hold entireness on Windows 2000/2003/XP with the cyberspace (using the accepted prescript protocols). UserGate crapper also impact on Windows 98 and Windows NT 4.0, but without NAT support. UserGate does not visit whatever primary resources for its operation; it exclusive needs a relatively diminutive turn of hornlike intend power for its store and index files. UserGate crapper also be installed on a sacred machine to tap your network’s resources.
Proxy Servers
Your scheme covering (whether it is cyberspace Explorer, Firefox, Safari, Netscape, Opera or Mozilla to study the most popular) is already healthy to store documents. However, momentous round expanse is not distant for these purposes if the cyberspace unification is mutual by an whole office. The think for this is that the quantity of digit mortal temporary the aforementioned scheme pages is farther inferior than if mountain or hundreds of grouping are distribution the connection. Creating a ordinary store for a consort crapper greatly modification bandwidth squander as substantially as attain nearly fast the acknowledgement of documents that are commonly accessed by employees. UserGate Proxy Server crapper also unification with the outside fall agent servers (of your cyberspace Service Provider) to process the pace of receiving accumulation and turn your cyberspace bills (traffic costs for a bourgeois are commonly inferior when a agent machine is used).
Program Configuration
Configuring the store settings is finished from the «Services» page. The prototypal travel is to enable the cache, then you crapper ordered its removed options, which earmark caching of POST requests, impulsive objects, cookies, and prescript content. You crapper also ordered the filler of the round expanse for the store and the time-to-live of cached documents.
Other options staleness also be ordered before you crapper move employed with the program. As a rule, this duty is complete in the mass order:
1. Create users of the program.
2. Configure DNS and NAT on the UserGate server. At this initiate you crapper configure NAT using the wizard.
3. Set parameters of the assorted protocols (HTTP, FTP, SOCKS), the intranet programme on which they power be listened for, and whether cascading power be done. All of these crapper be ordered at their aforementioned pages of assist settings.
4. Configure the meshwork unification on apiece machine computer, including gateway and DNS in prescript in meshwork unification properties, which staleness be set.
5. Create an cyberspace admittance policy.
Modules to Make Things Easier
To attain the aggregation more user-friendly, we separated it into individual modules:
The Server power is started at a machine that has cyberspace access. This power controls the enforcement of every tasks.
UserGate brass is performed with the hold of a primary module: UserGate Administrator, which handles every machine settings.
UserGate Authentication Client is a machine covering installed on apiece user’s computer. This power monitors and controls individual dominance to the UserGate server, if you opt an dominance autarkical of IP or IP+MAC.
Security and Permissions
UserGate Proxy Server locks discover unlicensed access. Each individual crapper be commissioned automatically by their IP come lonely or by a precise compounding of IP and element (MAC) address. Each individual crapper be appointed limited permissions
To attain it cushy to add users and to apace distribute the aforementioned permissions to a assemble of kindred users a removed tender is provided for the managing of users and groups. Groups attain it cushy to curb users that should hit ordinary settings, including meshwork admittance and rates. You crapper create as whatever groups as you need. Groups are commonly created supported on consort scheme and hierarchy.
Each assemble crapper be presented its possess evaluate that is utilised to curb cyberspace admittance expenses. A choice evaluate crapper be ordered or mitt empty, in which housing the connections of every users in a assemble are not paying unless a assorted evaluate is ordered in a user’s possess properties.
There are a sort of choice NAT rules provided in the program. These are admittance rules finished Telnet, POP3, SMTP, HTTP, ICQ and added protocols. While environment assemble properties you crapper refer which rules power be practical to the assemble and its users.
A selector on obligation choice crapper be utilised when an cyberspace unification is finished a modem. In this housing the modem dials up the unification exclusive when it is requested. Dial on obligation crapper also be utilised with ADSL, if in visit to intend adjoining to the cyberspace bourgeois it is needed to selector up a VPN connection. In this housing the VPN unification crapper be ordered as selector on demand.
If a machine with UserGate is in an Active Directory domain, users crapper be imported to it and then separated into groups that requirement kindred admittance rights: dominance type, rate, NAT rules (if assemble rules do not full foregather the user’s needs).
Authorization Types and Rules
UserGate Proxy Server supports individual dominance types, including dominance finished Active Directory and Windows Login, which allows desegregation UserGate into existing meshwork infrastructures.
UserGate uses its possess machine marker power for whatever types of authorization. Depending on the identify of dominance you opt it is needed to indicate, in individual options, either the user’s IP come (or IP come range), distribute a login (username and password) or distribute meet a username. If you poverty to beam to a user, reports of their cyberspace reciprocation ingest you crapper start the user’s e-mail here.
UserGate rules crapper be more flexibly organized than RRAS Remote Access Policy. Using rules you crapper hair admittance to limited URLs, bounds reciprocation on destined protocols, ordered happening limits, ordered a peak enter filler that a individual crapper download, etc. Windows does not wage the functionality needed to fit these tasks.
Rules crapper be created with the hold of the wizard provided. Each conception has covering conditions and an goal it is executed when digit or more conditions are met. For examples, near a connection, distribute a evaluate or speed, etc. Conditions earmark protocols used, happening of work, a user’s reciprocation limits (incoming and outgoing), money remaining on account, as substantially as, IP come itemize and come list. Settings also earmark the specifying of whatever enter extensions that users cannot download.
In a sort of organizations the ingest of fast messengers, much as ICQ, is prohibited. This is cushy with UserGate. To veto ICQ you exclusive create a rule, protection discover whatever unification with the patron ‘*login.icq.com*’ and administer it to every users.
UserGate Proxy Server provides rules to earmark varied rates for period or period happening access, to topical or ordinary resources (if much variations are offered by your cyberspace provider). For instance, for change between period and period rates digit rules are created: digit that performs the change at a immobile happening from period to period evaluate and the added that switches backwards to the period rate.
DNS and NAT Settings
DNS (Domain Name System) is what is utilised on the cyberspace so you don’t hit to advert a site’s drawing (its actual cyberspace address), much as 53.128.182.67), but instead you crapper meet advert its name, much as www.famatech.com. One of the controlling parts of the Internet’s DNS is the DNS server, which is a machine (there are whatever DNS servers) on the cyberspace that translates the obloquy of sites to their numbers, so when your covering goes to www.famatech.com, the DNS machine knows the precise IP sort to beam the covering letter to.
The DNS environment in UserGate Proxy Server is exclusive the locations (IP addresses) of digit or digit of these DNS servers (the fireman the DNS machine is to your ISP’s fleshly location, mostly the better), where apiece client’s DNS requests power be forwarded to. It is needed to inform the IP come in your meshwork programme of UserGate Proxy Server as the gateway and DNS in the prescript properties of apiece user’s meshwork unification on their topical computer.
There is added artefact to ordered the DNS. You crapper add a newborn NAT rule, in which the IP earpiece (the interior interface) and the IP communicator (the outside interface) are ordered to opening 53 and the prescript to UDP. If you ingest this method, this conception staleness be practical to every users. In unification settings of apiece topical computer, the IP come of the ISP’s DNS servers staleness be ordered as the DNS and the IP come of UserGate Proxy Server ordered as the gateway on apiece topical computer.
Mail clients crapper be ordered either finished opening function or finished NAT. If fast messengers are allowed to be utilised in the organization, the meshwork settings staleness be denaturized for them: both individual firewall and proxy, the IP come of the interior meshwork programme of UserGate Proxy Server staleness be indicated, and the prescript HTTPS or SOCKS needs be selected. If you ingest character Messenger, you should ready in nous that when you impact finished a agent server, Yahoo’s chitchat flat and transcription chats are unavailable.
Statistics for apiece individual are transcribed in a log. These earmark accumulation on the happening apiece unification started, its duration, amount cost, the URLs and IPs visited, the sort of bytes conventional and bytes sent. It is impracticable to equilibrate or misrepresent the transcription of whatever of this aggregation most individual connections in UserGate Proxy Server’s statistics file. The statistics crapper be viewed either from the Server Administrator or from a primary power Statistics. Statistics accumulation crapper be filtered by user, prescript and happening period; and these stats crapper be exported to Microsoft Excel for boost processing.
The primeval versions of UserGate Proxy Server cached exclusive prescript (web) pages. The stylish edition introduced newborn components fashioned to indorse aggregation security. Now UserGate users crapper verify plus of the built-in firewall and Kaspersky Antivirus modules. The firewall crapper curb (permit or block) limited protocol ports and crapper also publicize a company’s resources on the Internet. UserGate Proxy Server processes every packets conventional from the network. Every opening that is unstoppered in the program, for warning HTTP, SOCKS and others, are either designated by the chief or crapper be unsealed in the firewall automatically. You crapper wager which ports are unstoppered in the machine rules plateau on the Firewall Rules page.
Future utilization plans for UserGate Proxy Server earmark creation of its possess VPN server—so you hit an deciding VPN resolution to that offered by Windows—an launching of a accumulation machine that has its possess antispam hold and the utilization of an nimble firewall at the covering level.