NETFW.INF, Preconfigured Firewall settings and dialogs



Hi,

I'm in the process of finishing our standard, scripted build of Server 2003
SP1. I would like to pre-configure lots of the firewall settings, so that
some ports are open by default and others are listed in the firewall dialog
box to allow our admin staff just to tick the boxes rather than manually add
ports/apps. I know that this can all be done via the NETFW.INF file, and
have successfully got some of it working already.

However, for 'services' such as DFS, IIS, SNMP etc should I be adding the
individual ports, or should I be adding the service executable?. This
question applies to almost ALL of the services that 2003 can provide, as I'd
like a big range of entries that the support staff can simply tick:

e.g. for DFS, dfssvc.exe:*:Enabled:Distributed File System Service OR
ports 138,139,389,445 etc

I don't suppose that MS have a NETFW.INF that includes all the normal Server
2003 services do they? If not, this might be a useful thing to make
available.

All ideas/opinions gratefully received
Jim
--
Jim Watts,
Technology Consultant
Information Systems Services
University of Southampton


.



Relevant Pages

  • Re: Whats a decent modem/router for tech savy user?
    ... It is not possible to route or deny traffic to specific ports based on the source IP address. ... But it wont route back inside the LAN - needs internal DNS server spoofing. ... Normally, this option should be Enabled, so that an Internet connection will be made automatically, whenever Internet-bound traffic is detected. ... Specifying a Default DMZ Server allows you to set up a computer or server that is available to anyone on the Internet for services that you haven't defined. ...
    (uk.telecom.broadband)
  • Re: Cannot connect to RWW from home PC
    ... That would be the address you need a DNS record for. ... You say "And in the router you need to forward to your external nic IP" ... Still can't telnet to any of your ports at your public ip address. ... Heres' the info for our server: ...
    (microsoft.public.windows.server.sbs)
  • Re: Netopia 3347NWG with Remote Desktop and Remote Web Workplace
    ... Glad you're back in business Greg! ... Ports Closed ... Despite this, Remote Web Workplace DOES WORK now, and Connect to Server ... Exchange BPA updates), ...
    (microsoft.public.windows.server.sbs)
  • Solution -> Re: SSH tunnel question.
    ... change IPS and ports around but that is not a big deal. ... telnet/ftp/rsh open on a server including on the Internet facing ports! ... I will go from the corp desktop to a hop ... through the firewall to the hop ...
    (SSH)
  • Re: Exch2003 front-end questions
    ... all the supported protocol ports must be open on the inner ... communication between the front-end server and the back-end servers. ... lists the ports required for the intranet firewall. ...
    (microsoft.public.isa)