Where to begin; I am going to be running a security audit on a client's network. The client has yet to decide on any antivirus solution due to cost constraints. Being their project is nearly finished, a cost effective solution for AV would be useful. They are actually considering to rely on the Firewall's built-in AV and the end-user's AV installed locally. Their thoughts are to save money and keep a reduced load on a bloated server.
I am looking for those "expert" tips that may come in handy. Useful tools for security auditing would also be appreciated. This being my first audit, I am slightly intimidated by putting my seal of approval on the final product. With that said, I'd greatly appreciate any help, but I do ask that if you do provide a suggested solution, please explain and be as descriptive and detailed as possible.
Network Details:
Server 2003 Std.
Exchange Server 2003
Hosting Exchange Server with Webmail (No SSL)
WiFi available on wireless-g signal WPA-2
Print Server (20 Printers)
DHCP Server
Terminal Services enabled and broadcasted to WAN (No VPN)
20-30 connected workstations internally
3-5 users connected remotely (5, being maximum and highly unlikely)
Sonicwall Firewall TZ 170 (Ehanced Firmware)
DMZ available but not in use
Using all content-type filters for web and email
Using wide variety of NAT and Routing policies (Suggestions on frequent holes would be appreciated)
VPN is available and configured, but not used due to several technical issues (Client is considering new end point)
5 inbound global IP addresses being monitored
Logs filed and cataloged very intensively
DHCP server on firewall is disabled and pointing to DHCP server listed above
Desire for site-to-site VPN may be a possibility
Backtrack 4 Live CD is of interest, but I have very limited knowledge of it's functionailty and capabilities. Is this a good tool to audit a Windows environment with?
I am more than willing to consider purchasing any software or hardware that may be of great use.
I will provide more details as they are requested. Thanks for taking the time to look at this, and I am eager to hear suggested.