Re: Please help with my lack of understanding
- From: "Charles Lavin" <x@xxx>
- Date: Wed, 12 Dec 2007 20:36:37 -0500
Then the trick is not to do what "most people" do ...
I never said to open the firewall to all traffic. When I set something like this up, I set up the firewall to allow VPN/PPTP/GRE traffic through to the server, and nothing else.
"Leythos" <void@xxxxxxxxxxx> wrote in message news:MPG.21c98ef396d430bb989895@xxxxxxxxxxxxxxxxxxxx
In article <1C1C1AC8-CF8E-48E1-BC74-3E1DD01A1659@xxxxxxxxxxxxx>, x@xxx
says...
If he's connecting from a Windows box (XP, Vista, 2000), it would be far
more secure to shut down the FTP server and have him connect via VPN
connection. Then he can copy the files to his PC via simple drag-and-drop.
And you don't have the FTP server exposed to the Internet.
Except that by VPN, since most people create an ALL PORTS + IP type vpn,
instead of just locking it down, he could use a real firewall and limit
ports through it to just FTP.
He could also setup FileZilla FTP with authentication and better
security and even limit the IP Range it accepts connections from.
I really dislike when people do VPN's that don't have the ability to
limit what comes through the VPN - as an example, when we create VPN's
for remote users we limit the traffic to just TCP 3389 and the single IP
of the terminal server that if their home/local computer is compromised
we don't get it (as only one measure of protection).
--
Leythos
- Igitur qui desiderat pacem, praeparet bellum.
- Calling an illegal alien an "undocumented worker" is like calling a
drug dealer an "unlicensed pharmacist"
spam999free@xxxxxxxxxx (remove 999 for proper email address)
.
- Follow-Ups:
- Re: Please help with my lack of understanding
- From: Leythos
- Re: Please help with my lack of understanding
- References:
- Please help with my lack of understanding
- From: t . kinser
- Re: Please help with my lack of understanding
- From: Charles Lavin
- Re: Please help with my lack of understanding
- From: t . kinser
- Re: Please help with my lack of understanding
- From: Leythos
- Re: Please help with my lack of understanding
- From: t . kinser
- Re: Please help with my lack of understanding
- From: Charles Lavin
- Re: Please help with my lack of understanding
- From: Leythos
- Please help with my lack of understanding
- Prev by Date: Re: SBS 2003 Premium + WAN ?
- Next by Date: Re: Backup Wizard Errors
- Previous by thread: Re: Please help with my lack of understanding
- Next by thread: Re: Please help with my lack of understanding
- Index(es):
Relevant Pages
|