Open ports.

keving98_at_juno.com
Date: 02/05/05


Date: 5 Feb 2005 12:13:22 -0800

I recently installed SBS 2000, including ISA 2000 and Exchange 2000, on
a clients server and I'm a little concerned about the fact that,
according to programs such as "Shields Up" (I do not want to instigate
a flame war about the merits of Shields Up however), a number of ports
are wide open. The client does run a mail server and uses Outlook Web
access so I presume that certain ports need to be open for their mail
to function properly.

My question is: how can I provide the maximum protection for my client
and still leave their mail server, etc... functional? I've installed
all the patches for ISA and Exchange. The ports that show as "open" on
"Shields Up" are 80; 110; 25; and 443. I know what these ports are
for. Can I, or do I need to, mask them from the internet? All of
these ports were open by default after installing SBS 2000.

I know Microsoft is part of the problem when it comes to security but
could the default configuration of ISA be dangerous?

Any help would be greatly appreciated.

Kevin G



Relevant Pages

  • RE: sloww web browsing
    ... and ISA 2004, the internet access became slower than it used to be. ... Open the ISA Server management console, ... Click Start, point to Programs, point to Microsoft ISA server, and then ... will you be able to access the internet from the internal client ...
    (microsoft.public.windows.server.sbs)
  • RE: OWA page not displayed Outside
    ... Open ISA 2006 management console. ... Expand the server node and highlight 'Monitoring'. ... Click 'Configure Firewall Logging'. ... |> internal client as both the web proxy client and firewall client? ...
    (microsoft.public.windows.server.sbs)
  • Has your problem been resolved
    ... username not showing in ISA log ... They probably aren't using the proxy server. ... Troubleshooting Client Authentication on Access Rules in ISA Server 2004 ...
    (microsoft.public.isaserver)
  • Re: ISA firewall block outgoing email.
    ... I cannot send/receive email to the POP3 account unless I turn off the firewall in the CEICW. ... (This server is behind a router so I felt the test was safe enough to turn off the firewall). ... As I said, there is no need to add a hole for port 110, If the ISA client is installed on the workstation, Outlook will deliver the email. ...
    (microsoft.public.windows.server.sbs)
  • RE: SBS PE - Unable to establish Outbound VPN
    ... connect to an external VPN server through SBS with ISA 2004 or VPN to SBS ... the firewall client application identifies the internal/external ...
    (microsoft.public.windows.server.sbs)