Thanks Re: Security Issue (Protect How?)

From: Jpt (balda@ost.po)
Date: 02/03/03


From: "Jpt" <balda@ost.po>
Date: Mon, 3 Feb 2003 20:26:52 -0000


Thanks...its done

"x y" <levinson_k@despammed.com> wrote in message
news:Odaso4wyCHA.1624@TK2MSFTNGP11...

"Jpt" <balda@ost.po> wrote in message news:uZPi$dwyCHA.2648@TK2MSFTNGP11...
> Hi, i have my Web server running, but regard to security i have nothing.
> What can i do in order to protect my Server?, can i install a firewall and
> only make avaiable ports 80 and 21??. What options do i have?

First, you want to harden Windows and IIS:

http://securityadmin.info/faq.htm#harden

A firewall is a very very good idea. There are even free ones available.

http://securityadmin.info/faq.htm#firewall

Destination port TCP 80 inbound [and the replies back out] are necessary for
HTTP / web.

FTP requires TCP 21 and also either TCP 20 or a randomly selected TCP port
for the second "data" channel, depending on whether the FTP client and you
want to use Active or Passive FTP. Search www.google.com for something like
"active passive ftp firewall" to find out how the rules should be set up.

If you have your own DNS servers, you might also need to permit destination
TCP and UDP ports 53 inbound.

Other options for securing a web server are at:
http://securityadmin.info



Relevant Pages

  • Re: Security Issue (Protect How?)
    ... > Hi, i have my Web server running, but regard to security i have nothing. ... FTP requires TCP 21 and also either TCP 20 or a randomly selected TCP port ... "active passive ftp firewall" to find out how the rules should be set up. ... TCP and UDP ports 53 inbound. ...
    (microsoft.public.inetserver.iis.security)
  • Re: How to close ports and which ones
    ... In your firewall, close all ports, then open only what you need. ... you run a web server you'll need TCP 80, DNS would need UDP 53 and TCP ... Use the IIS Lockdown tool ...
    (microsoft.public.windows.server.security)
  • Re: Just added router and now cannot connect to web site from outside
    ... You need to forward the ports to your web server. ... (Port 80, TCP) ... I have been looking at the configuration screens ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: security advice (possible hacker activity?)
    ... Well, it's entirely up to you, but usually blocking all ports both outbound ... trojan or worm is installed onto the web server. ... the IIS web server. ...
    (microsoft.public.inetserver.iis.security)
  • Re: security advice (possible hacker activity?)
    ... Well, it's entirely up to you, but usually blocking all ports both outbound ... trojan or worm is installed onto the web server. ... the IIS web server. ...
    (microsoft.public.win2000.security)