Watching for RWW breakins



I'm nervously configuring RWW for our SBS 2003 Standard server (2 NICs &
router). I'm doing everything I can find to protect it, including changing
the Administrator account name, setting really obnoxious passwords, setting
IP address filters in the router, and forwarding a nonstandard port to 443
for HTTPS access.

My question is: How do I tell if I'm unsuccessful? Other discussions here
have emphasized monitoring the security log, but what on earth do I watch
for? On our little network (~10 workstations) the security log gets 25-40K
entries per day; I had to increase the log size to 100Mb to hold a week's
activity. In the last 24 hours, it shows 11,500 event 540 (successful
network logon) including about 100 Administrator logons, many of them in the
middle of the night. Is there a way to filter the security log to sort out
RWW logons? Is there something else I can be monitoring?

(Put me down as one more vote for being able to block Administrator from RWW.)

Thanks a ton.
.



Relevant Pages

  • Re: Grey screen after login to 2003 TS
    ... Anything in the EventLog, especially the security log? ... I believe that this can happen when users have too few permissions on ... Run them as administrator (when no user ... MCSE,CCEA, Microsoft MVP - Terminal Server ...
    (microsoft.public.windows.terminal_services)
  • Re: Is there a way to query Security Event Log with Filter in C#?
    ... I am login as an administrator on my Win2k server. ... have over 55k of entries in Security log in Event Viewer. ... ManagementObjectSearcher mos = new ManagementObjectSearcher; ... foreach ) ...
    (microsoft.public.dotnet.languages.csharp)
  • Re: Server 2003 updates fail
    ... Some how the administrators was removed from Manage auditing and security log in the local security setting. ... > Please verify permissions on the following rights include the built-in ... I was log on as the administrator when getting ...
    (microsoft.public.windowsupdate)
  • Re: Error Reading the Security Log
    ... Can you elaborate on your comment? ... >>I am getting this error when I try and read the events in the Security log. ... > Make sure you are effectively impersonating an Administrator. ...
    (microsoft.public.dotnet.languages.csharp)
  • clear login cache
    ... Ask your Desktop Administrator to boot your windowsxp into Local Machine Administrator logon, ... Double Click on Local Security Policy icon ... Privius logons to cache(In case domain ontroller ...
    (microsoft.public.windows.server.general)

Loading