Alright, I was saving up this post for when I had time to comment. (I went to see Tran-Siberian Orchestra Yesterday ^__^)
So, let's see here where do I begin... Background: Alright, So I work in a Social Security Disability Law Firm, I am called the IT guy, but if I wanted to put it into professional terms I label myself as the Senior Network Engineer. Yes, I said Engineer, I'll get to that in a minute... So, this place is a "Mac Only" law office, as my boss has only been using Mac's since 1985, and he is such a tech idiot, he still doesent know a single keyboard shortcut (including copy/paste) and still hasn't figured out how to scroll with a mousewheel/magicmouse/mightymouse....
When I got their I almost panicked... 30 computers, almost half of the workstations (Remember all macs) on an insecure wifi, no backup solution no central point of storage other than a flash drive plugged into the apple airport extreme.... >:-o Let me repeat myself... We are a Social Security Disability Law Firm and Had NO SECURITY, medical records, social security numbers, personal addresses, names and god knows what else was flying through the air on a N network in CLEARTEXT. In fact I showed my boss this one day as we had coffee across the street from our office, and he still did not panic as much as I was.
So in my time there, I have preached the value of security day in and out, although it took 2 years of me preaching I finally got my way, and we invested in wired networking, hardware firewall, switching equipment, a DD-WRT router (ASUS N16) that can handle the load, and since we are mac only a mac mini server. I was impressed with the out of box security that this little server had to offer, and I was also impressed that apple actually allows me to do what I want on the device, It is basically like running full freebsd with an aqua shell. I set up an active directory server, using kerberos identification, a print server, share points, an ical server, dns server and a mail server. The thing only took me a day to configure. (I needed a little help with permission rights on the share point and had to call apple enterprise support which was not only free but AMAZING.) The server was also very easy to make sure it was backing up, it has two hard drives, so I made a very simple script using automator which automatically copies our work files, compresses them and then uploads them to not one but two remote FTP servers we have purchased for the next 5 years. Working on it is a breeze, it doesn't have a keyboard, mouse or monitor attached but all I have to do is use a different mac using share screen, or simply I can use the server applications programs locally if it isn't to intensive.
If you were questioning about security, yes the mac mini server came with the firewall defaulted to on. I have attempted a many attacks trying to get in and have yet to be successful. I feel the system is secure enough for a 30 person office now. Overall I am happy with the setup, not to complicated, but also well. The employees LOVE the open directory server as everyone has their own login accounts now and they replicate at any workstation they log into, and the mail server and ical server helps keeping the office on task is very nice. All and all I used to be a mac hater, but then I used OS X server, and I gotta say it is a powerful setup in compairson to M$ Active Directory Service.
Any questions about the Mac Mini Server go ahead and ask. As a brief note it is running OS X server 10.6.x