Re: SBS2003 Firewall Question



Control Panel | Administrative Tools | Routing and Remote Access |
[SERVER_NAME] (local) | IP Routing | NAT/Basic Firewall

You should see 4 entries in the right pane: Loopback, Internal, Internal,
External NIC

Double-clicking on the External NIC should show (under the NAT/Basic tab):
Public Interface Connected to the Internet (with both Enable NAT and Enable
Basic firewall checkmarked).

--
Merv Porter [SBS-MVP]
============================

"Richard K" <RichardK@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:3B9D68E4-D167-4ACF-AAEC-A4382F17484C@xxxxxxxxxxxxxxxx
What do I look for in the RRAS Console to verify firewall?

"Merv Porter [SBS-MVP]" wrote:

If they have 2 NICs in the SBS server and have run/configured CEICW
properly, the NAT/Basic Firewall in RRAS should be in effect. You can
check
this in the RRAS console. (I would prefer to see a cheap router between
the
broadband modem and the external NIC - slight increase in security and
easier to troubleshoot network problems since you can connect a laptop
directly to a router port to "remote" into the server, thus taking the
router config out of the troubleshooting equation).

I don't use Symantec AV, but I found this info:

What's new in Symantec Client Security 3.1
http://service1.symantec.com/SUPPORT/ent-security.nsf/ppfdocs/2006021515052848

"Exchange scanning improvements: Provides automatic exclusion of files
and
folders from scans when an Exchange server is present on the computer
where
Symantec AntiVirus is installed. Administrators no longer have to exclude
files and folders manually."

--
Merv Porter [SBS-MVP]
============================

"Richard K" <RichardK@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:411DEE66-E522-4407-A23D-208835C0EF4F@xxxxxxxxxxxxxxxx
I have a new client that I am bringing on board. After checking out
their
SBS 2003 server setup here is what I find

1. SBS 2003 Standard (not premium, not even R2)
2. Dual nic with ISP side direct connect to DSL modem, no router in
between
so I am assuming all ports open to server like a dmz from the dsl line.
3. Windows Firewall not enabled. (Try and load up via Control Panel
and
I
get "Windows firewall cannot run because another program or service is
running that might use the network address translation component
(ipnat.sys)"
4. I can't see any other programs that may be doing firewall but they
do
have Symantec Client Security but I suspect that is AV for server and
clients
and may not even be doing email checking. Not as familier with the
Symantec
product.

Since this is only Standard they are not running ISA. No router on ISP
side
to at least filter ports. With what I see am I assuming correctly that
no
firewall is working at all for them and they are wide open? Am I
assuming
correctly that with the Symantec product they are not even checking
email
for
viruses?





.



Relevant Pages

  • Re: loss of SOME connectivity
    ... I "think" it is DNS. ... Yes, I can ping the router, AND the ISP DNS. ... I cannot connect the inet cable directly to the server because the inet is ... MS firewall not started. ...
    (microsoft.public.windows.server.sbs)
  • Re: IP Addressing
    ... Address of the ISA server? ... firewall and router). ... On the firewall create a static NAT entry as I wrote ...
    (comp.dcom.sys.cisco)
  • Re: Still cant connect to RWW or OWA remotely
    ... Re-running the CEICW, disabling the firewall, then re-running CEICW again, ... "Cannot find server or DNS Error". ... the DSL router 4-port switch. ... of the two NICs by clicking the Advanced tabs, ...
    (microsoft.public.windows.server.sbs)
  • Re: VPN suggestions requested
    ... > connecting to the Internet through a cheap basic broadband router. ... necessarily mean you have to pop in a firewall, ... also mean only to secure the W2K server. ...
    (comp.security.firewalls)
  • DLink 704 hangs, so I need something better
    ... I recently purchased a DLink 704 firewall/router to hold the static IP ... It works well as a standalone firewall, ... Every consumer-level router in the world has this feature. ... Can Windows 2000 Server perform the same type ...
    (comp.security.firewalls)

Quantcast