[There's a reason that Yoda is the unofficial mascot of SBS.  Size indeed matters not.] My way is better... no MY way is better - THE OFFICIAL BLOG OF THE SBS DIVA
Wed, Jul 21 2004 23:47 bradley

My way is better... no MY way is better

“One nic [network card] is better than two nics“

“A hardware firewall is better than a software firewall“

I was reminded by these “mine is better than yours” by a post by Rory.  He starts out by relating the story of Nike and how he thought if he only had the “swoosh” on his side, he'd be better, stronger, he'd be just ... just more.  Well he found out that shoes do not make the man.  He uses it as an analogy over “language wars”.

The same can be said in SBS land.  I'm guilty in the newsgroups of posting in a “pompous manner' oh don't do it with a one nic, always do it with two nics, but you know what?  I'm second guessing that consultant who [if they've done what they are supposed to do], analyzed the client, looked at the issues they face and determined the best solution.  At the same time, for all those folks that recommend one nic, don't blame me for liking and recommending two network cards.  I like having the separation and feeling like I'm doing it like the big boys. I'll paraphrase Rory's question but in the case of SBSland where we can do things in many many ways.....

1) Can it do the job well?

2) Can it do the job in a way which pleases you?

If you can answer "yes" to these two questions, then you have the right bloody “technology“, and don't let anybody tell you otherwise.

As long as both methods work, keep the networks safe, and provide that company with what they need, does it matter how you do it?  It provides a solution.  So let's get past arguing what is the “best practice“ as what is “best“ for you might not be “best“ for me.  The “best“ solution is one where the consultant has set up “the“ firewall [whatever brand], in a manner that it is controlled, auditable, confirmed to only have those ports open what is it was intended to have open, configurable only by those who are authorized to configure it, and without known vulnerabilities. As long as whatever technology is in place protects and defends that network exactly when it needs it, who cares what is used?

Filed under:

# re: My way is better... no MY way is better

Thursday, July 22, 2004 5:26 AM by bradley

Did this person post why they only use one nic? I also use hardware firewalls most times, but I do this to offset the load on the server since it is already running exchange, sometimes sql, and fp services. Not to say that ISA is a bad firewall as I have used it on a few SBS installs.

# re: My way is better... no MY way is better

Thursday, July 22, 2004 2:19 PM by bradley

Typically the one nic setup is perceived to be more secure because the "hardware" firewall is perceived to be more safe. I disagree as I would argue that firewall isn't patched as much it it's a hardware firewall.

Honestly this bit of "unloading the server" the ISA server can be tweaked to only use 10% of memory anyway. It doesn't overtax the server.