Re: Do I need a firewall

From: Brett (bbsouth@bellsouth.net)
Date: 02/05/03


From: "Brett" <bbsouth@bellsouth.net>
Date: Wed, 5 Feb 2003 08:23:06 -0600


"Leythos" <void@nowhere.com> wrote in message
news:MPG.18aac7d8d1666889989996@news-server.columbus.rr.com...
> In article <IdZ%9.2115$V32.633@news.bellsouth.net>,
> bbsouth@bellsouth.net says...
> >
> > "Leythos" <void@nowhere.com> wrote in message
> > news:MPG.18aa26357866c9b989991@news-server.columbus.rr.com...
> > > In article <CnT%9.214$eH1.80@news.bellsouth.net>,
bbsouth@bellsouth.net
> > > says...
> > > [snip]
> > > >
> > > > Ok on the Tracker troll.
> > > >
> > > > CF Sever and SQL Server are on the same box right now. I do
reference
> > the
> > > > box's IP address. I suppose I could just reference 127.0.0.1 and
that
> > would
> > > > keep my connection local correct?
> > > >
> > > > Still, if I am able to reference the box's Internet IP address, the
port
> > is
> > > > open. I'll need to read more on how to shut it off to external
> > connections
> > > > while allow it to be connected via 127.0.01.
> > > >
> > > > I'm still confused on what it means for SQL Server to be open to the
> > > > Internet. grc.com says 1433 is not open. What does that mean?
> > >
> > > Brett,
> > >
> > > If you can reference the SQL server port using the internet address it
> > > means your entire server must be exposed to the internet - Assuming
that
> > > you have a broadband or DSL connection, can you purchase a cable modem
> > > router to protect your network and server - this would mean that you
> > > would only forward port 80/443 inbound for your web server and the
> > > router would block all other inbound ports.
> > >
> > > One way to see if your SQL server is exposed is to open the Query
> > > Analyzer, enter the internet IP address of the server and the user/pwd
> > > an see if it connects. If you can connect, so can I from my home :)
> > >
> > > If you get a router then you will be a heck of a lot better off - it
> > > will block inbound ports unless you forward them to a local (internal)
> > > IP address. pointing to 127.0.0.1 will do nothing to protect you.
> > >
> > > --
> > > --
> > > Leythos999@columbus.rr.com
> > > (Remove 999 to reply to me)
> >
> > Thanks. After running unixcircle.com, I see quite a few ports are open.
> > Some I need to be open. Will a software firewall such as Zone Alarm
help
> > anything? It's a funding issue.
> >
> > Brett
>
> Brett, a software firewall is the base minimum you can start with, but
> $70(US) for a router at CompUSA or BestBuy is the better solution.

Not so. My hosting provider wants $140/mo for a firewall.

> Software firewalls will consume CPU cycles and memory as the port probes
> increase, if you get the router it will block the probes and you
> firewall will only report on things that actually get IN to the
> computer.
>
> The only ports you need open are 80/443 and possibly FTP. The rest
> should be closed for any CF server. I manage a group of CF developers in
> another state, they do fine with 80/443 open only. They VPN into the
> firewall and then get access to the servers if they need anything else.
>
> --
> --
> Leythos999@columbus.rr.com
> (Remove 999 to reply to me)



Relevant Pages

  • Re: Port 135
    ... The patch doesn't disable DCOM / RPC, so connections can still be made. ... That's why you need a firewall. ... the patch is not the thing to control ... control over your TCP/IP ports and services, ...
    (microsoft.public.security)
  • Re: Got Active Ports, now what?
    ... have services running and ports open does not in ANY way shape or form mean ... vulnerabilities and links to plenty of other ... Why do I need 23 connections to the ... > You should get a 'Application' Filtering Firewall for your XP box. ...
    (comp.security.firewalls)
  • Re: File sharing
    ... Instead of creating exceptions for individual ports for FPS I suggest that you try Group Policy and configuring the exemption for file and print sharing and probably the remote administration exemption. ... If there are do domain level Group Policies being applied to these computers currently for Windows Firewall, which you could verify by running rsop.msc on the client computer, you could try using local Group Policy to see if it does what you want. ... So then I went back and put in a custom setting to accept connections on the local subnet plus connections from my subnet, ...
    (microsoft.public.windowsxp.security_admin)
  • Re: SQL Server 2005 Transaction VPN Firewall
    ... den MSDTC habe ich eingerichtet, wenn ich die Firewall alle Ports aufmache, ... Kann man die Verbindung nicht auf einen festen Port legen? ... wie geht das in SQL Server 2005? ... Ports da genutzt werden. ...
    (microsoft.public.de.sqlserver)
  • Re: On passwords, securtiy and real -sweat, blook and tears- life
    ... given that all ports are closed to external contact through a physical allbeit consumer oriented firewall, just means I am safe for port-scanners. ... connections reduces the risk a lot. ... you can boot in single user mode and change the password. ...
    (Fedora)