Re: Firewall for Windows 2003 Server R2 Standard



When Google I got the below reply:
--------------------------------------------------------------------------
Who are these "Windows Gurus" that you have spoken to, and what was the
exact question/answer (and context)?

IPSec, for example, is supported in Windows 2000 and Windows 2003, and can
give you very good protection (barring possible vulnerabilities in the
implementation), so whoever told you that there's "no good way" is either
qualifying their comments, or doesn't know what they're talking about (an
example of a qualification would be that IPSec isn't a firewall in a literal
sense).

Windows Server 2003 also comes with the built-in ICF as well, which, again,
may be "good enough" for you (though I would look at IPSec first).

Personally, I feel that the common SOHO type"Personal" software firewalls
(eg ZoneAlarm) do not give you enough flexibility to be able to configure
them appropriately for a server (given that you want to open a number of
ports). Most are designed for people who need to secure a client machine (ie
not allow incoming connections, but allow some applications outbound access
to the 'net). A lot don't give you much granularity either (for example, you
can specify that your email app can go out onto the 'net, but you can't say
that:
- email app can connect to pop3.myDomain.com port 110
- email app can connect to smtp.myDomain.com port 25
- deny access to everything else (eg everything port 80 to stop web-bugs
embedded in HTML mail)

You need to look at the more sophisticated products (though still "Personal"
products), such as Sygate's product (www.sygate.com), Kerio's Personal
Firewall product (not supported on Windows 2003 Server yet) (www.kerio.com)
or Tiny Software's (www.tinysoftware.com/) firewall product. Each of these
allows you to nominate an application/executable, and which IP
addresses/subnets can access (or are barred access) to which local and
remote ports, for which protocol (UDP/TCP/ICMP) inbound and or outbound.

That said, I believe that a separate hardware device (whether dedicated like
a Cisco PIX, or application layer like Microsoft's ISA server) provides a
more robust, and secure environment (however you need to weigh up whether
you can afford the cost!)

HTH

Cheers
Ken

Microsoft MVP - Windows Server (IIS)

--------------------------------------------------------------------------


.



Relevant Pages

  • LPD/LPR printing or alternative
    ... Configuring LPD for Microsoft Windows XP or Windows 2003 Server ... LPR port. ... protocol address of the HP Jetdirect print server. ...
    (comp.os.os2.misc)
  • RE: Printing from Win9x clients stops
    ... since this issue only occurs on all Windows 9x ... Open Server Management Console, ... Verify basic network connectivity. ... >> Create a local printer and in the Ports section, ...
    (microsoft.public.windows.server.sbs)
  • Re: keeping ports open
    ... If a port is open, it means that 1) a software or service is running on your ... and 2) you're not using a firewall or your firewall isn't ... Use firewall software and hardware and antivirus software that is ... Follow the instructions for hardening Windows and IIS at ...
    (microsoft.public.security)
  • L2TP/IPSec Verbindung läuft mit XP SP2 nicht mehr
    ... workstation2 mit Windows.xp SP1a und IPSec NAT-T Traversal Update, ... Windows 2003 VPN RRAS Server, ...
    (microsoft.public.de.german.windowsxp.networking)
  • [Full-Disclosure] ron1n phone home, episode 4
    ... Hacking from Windows 3.x, 95 and NT ... Use secret Windows 95 DOS commands to track down and port surf computers ... Download hacker tools such as port scanners and password crackers designed ... Now you have the option of eight TCP/IP utilities to play with: telnet, ...
    (Full-Disclosure)