Re: Danger to having Port 80 open on hardware firewall

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Kevin Weilbacher [SBS-MVP] (kweilbacMVP_at_gte.net)
Date: 03/21/04


Date: Sun, 21 Mar 2004 14:25:27 -0500

Steven, I have setup two SBS2003 systems, with SSL Certificate defined, and
neither will allow me to use http://fqdn/remote remotely ... I must use
https://fqdn/remote

-- 
Kevin Weilbacher [SBS-MVP]
"The days pass by so quickly now, the nights are seldom long"
"Steven Banks [SBS MVP]" <steve@newsonline.banksnw.com> wrote in message
news:OdW2aXxDEHA.548@TK2MSFTNGP10.phx.gbl...
> John,
>
> By design, when you type in http://fqdn/remote it should connect and
> immediately switch to https://fqdn/remote.  Is this happening for you?  If
> not, ensure port 443 is enabled as the SSL port for the default Website
and
> that you have your server's cert showing under the Directory Security
> Properties of Remote.  If it is still not switching to SSL, then re-run
the
> CEICW.
>
> To answer your first question, If port 80 is really bugging you, you can
> always take it out.  If your server is patched up to date and running
> current AV software and is behind your firewall, your exposure on port 80
is
> a low risk in my opinion.  If you don't patch and keep current AV software
> running, then you'll be hit over port 25 from email based worm/virus
attacks
> long before port 80 becomes an issue most likely.
>
> Steve
>
> -- 
> Banks Consulting Northwest
> http://www.banksnw.com
>
>
> "John" <jk@rt.com> wrote in message
> news:OqCdyhwDEHA.2908@TK2MSFTNGP09.phx.gbl...
> I am running SBS2003 standard with a dual NIC configuration and Linksys
> firewall.  I do NOT have the root setup to publish a website.  I have
found
> that if I have port 80 forwarded to my WAN nic I am able to access RWW by
> typing fqdn/remote  instead of https://fqdn/remote.  I have closed the
port
> for now but am curious if this is a bad idea just to gain some
convenience.
>
> TIA
>
> John
>
>
>
>


Relevant Pages

  • Re: client end of ssl authenticaiton
    ... windows xp setup with outlook quit working too, ... shows port 465 will be used. ... In the setup it did indicate it would be using ... check box for ssl which also indicated it would use port 465. ...
    (comp.mail.sendmail)
  • Re: Installing ISA Server for first time
    ... Please note that though correct for HTTP SSL on non standard ports I'm not ... the ISA 2004 can only allow SSL 443 port go through it. ... Microsoft is providing this information as aconvenience to you. ...
    (microsoft.public.windows.server.sbs)
  • Setting up OWA SSL on a non-standard web port.
    ... certificate authority so that I could run SSL for the ... So I switched my IIS to port 80 to test it out and low ... enable SSL is there a way to setup the SSL authentication ...
    (microsoft.public.exchange.setup)
  • Re: Self Signed Certificates
    ... RWW works fine using SSL port 443. ... My config for the site is using port 444, windows authentication, SSL is ...
    (microsoft.public.windows.server.sbs)
  • Re: Installing ISA Server for first time
    ... the ISA 2004 can only allow SSL 443 port go through it. ... Microsoft is providing this information as aconvenience to you. ...
    (microsoft.public.windows.server.sbs)