Re: [fw-wiz] Too Paranoid?

From: Paul D. Robertson (proberts@patriot.net)
Date: 09/29/02


From: "Paul D. Robertson" <proberts@patriot.net>
To: Jim Seymour <jseymour@LinxNet.com>
Date: Sun Sep 29 12:12:02 2002

On Sun, 29 Sep 2002, Jim Seymour wrote:

> Hi,

Hi Jim,

> it. Proprietary server software runs on this server and proprietary
> software to talk to the server runs on one-or-more MS-Win desktops.
> They use ActiveX controls. The server, in turn, must communicate

What protocols does the desktop<-> server stuff need? It seems to me that
the best bet would be to put the 2k server outside the firewall on a
service network and allow the clients to go out and access it, but this
assumes some level of control over the client<->server protocol (if it's
just TCP-based one-off stuff, I think you're still better off, if it needs
NetBIOS or RPC, then it's probably just going to suck no matter what.)

> Here's the problem. Certain third-party modules the server software
> uses to communicate to other servers on the 'net don't seem to be
> able to deal with the proxy server on the firewall. They're given
> the IP address and port number, but they won't work that way. The
> vendor of this lash-up wanted me to punch a hole through the
> firewall for port 443.

Even if they tunneled well, I'd still want the thing cordoned off from my
internal network and forced to talk nicely with the specific desktop
clients.

I've had this fight with personnel/benifits systems before, and once we
got to the "it needs these two TCP ports" place, isolating it wasn't all
that difficult.

Paul
-----------------------------------------------------------------------------
Paul D. Robertson "My statements in this message are personal opinions
proberts@patriot.net which may have no basis whatsoever in fact."
probertson@trusecure.com Director of Risk Assessment TruSecure Corporation



Relevant Pages

  • RE: Some technical errors
    ... If the SMTP server is not running on port 25 TCP it is not a public ... Manager - Computer Assurance Services BDO Chartered Accountants & ...
    (Security-Basics)
  • Re: SRV RRs support in Internet Explorer?
    ... The port number could be implicit (i.e. ... At any point in time, a server could fail ... can't effectively LB or backup because NSs cache the records for the TTL ... I still don't see how SRV records would help backup or LB. ...
    (microsoft.public.win2000.dns)
  • Re: Still cant connect to RWW or OWA remotely
    ... I get 'cannot find server or dns error' on both ... TCP [port number]> to open the ports. ... As for error messages when I fail to access RWW with the laptop, ... network, no connection seems possible. ...
    (microsoft.public.windows.server.sbs)
  • Re: Outlook 2003 client
    ... Items' folder from the Send/Receive group for my account, ... Send/Receive to synchronize Outlook local data with the Exchange Server, ... Port 21 enable external and internal file transfer ... Port 80 enables all nonsecure browser access, ...
    (microsoft.public.windows.server.sbs)
  • RE: SMTPS - Exchange
    ... Microsoft CSS Online Newsgroup Support ... This newsgroup only focuses on SBS technical issues. ... If the Exchange server is listening on other port rather ...
    (microsoft.public.windows.server.sbs)