Re: Port Forwarding

Tech-Archive recommends: Fix windows errors by optimizing your registry



In news:78FAB2EE-38BC-4D01-8A86-E5B62F498698@xxxxxxxxxxxxx,
BenP <BenP@xxxxxxxxxxxxxxxxxxxxxxxxx> typed:
Hi Lanwench

Thanks for that.

I plan to close all the ports I can, once I know what ports the mx
record my domain name is sending. I have been told that is mite be
110 but I am not sure.

No. It's 25. *Everything* should be closed unless it is not needed - this
is true even for testing. It takes only a few nanoseconds for uninvited
visitors to get into your network.

As for the FTP server being in the DMZ, I am planning that once I
figure out how to do it with our existing hardware, our firewall is
built into our router. The FTP server is not high on my list of
things to sort right now.

Do not open up FTP access to a server on your LAN. This is a bad idea from a
security standpoint. Remember, it isn't malicious individuals you need to
worry about - there are lots of port scanners & zombie machines out there.


My main consern is sorting the port issue, and then working out why I
am having emails rejected from our SMTP. I have found out from AOL
who are rejecting our mail that:
The IP address you have supplied - xx.xxx.xxx.xxx - is listed as a
dynamic address on the MAPS DUL



I have requested that we are removed from this list but not heard
anything back as yet

In the meantime, you could try forwarding your outbound mail (esp to AOL) to
your ISP's SMTP server as a smarthost.



Thanks
Ben

"Lanwench [MVP - Exchange]" wrote:

In news:FF47EDA8-2625-4B6F-A5B2-35EC0F8247F7@xxxxxxxxxxxxx,
BenP <BenP@xxxxxxxxxxxxxxxxxxxxxxxxx> typed:
Hi all

Just a quick question, I have had my ISP forward our MX recort to
our static IP address. I have also setup that all ports are
forwarded from the router to our Exchange Server on our network.
Everything is working very well, even the smtp server I setup
works, but I am very worried about the security issue of having all
ports open on the router.

Does anyone have a list of ports I should and should not open, I am
running Exchange on one server, and a ftp & smtp server on another.
Exchange is on s Win2K3 SBS Enterprise R2 server and the ftp & smtp
server is on Win2K.

Thanks
Ben

P.S. I am also trying to get remote desktop working on Windows 2000
server

As to the ports you shouldn't have open - well, hard to say, but in
general, you should have none that you don't need, and none that are
going to invite trouble into your network. It would be easier to
answer your question if you posted a list of ports you have
open/forwarded now.

What is the other SMTP server for/ what is it doing now?

If you must use FTP, don't put it on your LAN - put it in your DMZ.



.



Relevant Pages

  • Re: passiver FTP auf windows server 2003
    ... aber nur bestimte Ports per TCP/IP ... Dies ist dann das Problem beim passiven FTP. ... Ich hoffe Du hast noch sowas wie eine Firewall vor dem Server stehen, ...
    (microsoft.public.de.german.windows.server.setup)
  • Re: FTP server behind NAT using Kerio
    ... > I have a Windows 2000 FTP server running behind a Linksys DSL router. ... it is ftp at work. ... > Can I open up a range of outgoing ports for IIS? ...
    (comp.security.firewalls)
  • Re: Whats a decent modem/router for tech savy user?
    ... It is not possible to route or deny traffic to specific ports based on the source IP address. ... But it wont route back inside the LAN - needs internal DNS server spoofing. ... Normally, this option should be Enabled, so that an Internet connection will be made automatically, whenever Internet-bound traffic is detected. ... Specifying a Default DMZ Server allows you to set up a computer or server that is available to anyone on the Internet for services that you haven't defined. ...
    (uk.telecom.broadband)
  • Re: ServU-deamon trojan warning with McAfee
    ... FTP FTP FTP. ... You did it to yourself by having FTP server on your SBS box without the ... > software didn't pick up this infection altough the DAT file included the ... > document what ports need to be opened and for what reason? ...
    (microsoft.public.backoffice.smallbiz2000)
  • About utility of a firewall with win2000 server
    ... I'm configuring a webserver. ... It will be used exclusively for web services (http and ftp). ... All the ports are opened as soon as an IP adress is affected? ... dans un datacenter. ...
    (microsoft.public.win2000.security)