Re: SBS FTP service getting slammed.



I do not think static is important for this specific purpose as long as
you can distinguish by IP or subnet the machines that should be
allowed to access FTP. That would be sufficient to define a filter
in an IPsec policy to limit FTP access.
If you are entirely protected by firewall from outside, then either
the FTP is being hammered by an inside machine or the firewall
configuration needs reevaluation.
If you have SBS03 Premium, then are you using ISA ? This
could form a second layer after the hardware firewall, and the
ISA could be using authentication based on your Windows
accounts to gate access whereas the firewall would narrow
down what comes at you edge machines.

"Purtech" <mikek(remove)@hlit.net> wrote in message
news:uFfg47ceGHA.3952@xxxxxxxxxxxxxxxxxxxxxxx
Roger:

It is SBS 2003 Premium.

These machines are external - without static addresses for the most part.

My server is dual NIC but I use it for Load Balancing. The entire main
office is protected by a hardware firewall.

I will consider your suggestion about the NICs.

Question: is having static addresses one of the best/least complicated
ways to solve this? I ask becuase I might take your answer to my boss to
get the money approved for it.

Mike


"Roger Abell [MVP]" <mvpNoSpam@xxxxxxx> wrote in message
news:uNmI8$UeGHA.3484@xxxxxxxxxxxxxxxxxxxxxxx
You have not indicated OS versions.
If SBS is W2k based then use IPsec in a filtering mode, else if
this is SBS based on W2k3 use either IPsec in a filtering mode
or use the W2k3 firewall or use boh
in either event with the objective of allowing the FTP ports only
for the IPs of the machines that do need FTP access for the
(internal I assume) backup purposes.
Now, the above can be used whether the SBS server is a one
nic or two nic server. However, if it is a one nic server you
should consider making it into a two nic server with all of your
infrastructure off the new internal nic and with the (ISA if you
SBS version permits) protected external nic allowing only what
is absolutely necessary (ex. DNS, time service, SMTP/Pop,
http/https, vpn). Ideally you would have the external nic also
behind at least an inexpensive firewall/router.


"Purtech" <mikek(remove)@hlit.net> wrote in message
news:uf4YvUQeGHA.3388@xxxxxxxxxxxxxxxxxxxxxxx
We have a low IT budget. I am using FTP to backup remote computers.

Someone discovered my FTP service was opened and has been hitting me
with 10's of thousands break-in attempts. Usually trying the
administrator user.

They will probably not figure out the user name, because I have changed
the admin username, but it is almost everyday.

Yesterday they tried the username of "Julian" Go figure. The police here
won't do anything. Neither will my ISP.

Any ideas?

Thanks!







.



Relevant Pages

  • Re: 2 PCs not visible in net view or network browsing - Why?
    ... > it is the SAME as the Primary DNS suffix -- but this is NOT ... :yes some are public but behind firewall, so only visible to local domain.. ... Between the working machines ... > Are you using a DC for a router (multiple NICs)? ...
    (microsoft.public.win2000.networking)
  • Re: SBS FTP service getting slammed.
    ... We have SBS Premium 2003. ... The FTP client is now authenticating to the server. ... I am not using the 2003 firewall, like I said, just the hardware ... I will consider your suggestion about the NICs. ...
    (microsoft.public.security)
  • Re: Backup for win2k boxes in the DMZ
    ... I agree you should not rely exclusively on a firewall. ... they still have access to your internal network without going through ... the firewall if you straddle the firewall with a machine with two nics. ... I agree with all your points about making sure the inside machines are ...
    (Security-Basics)
  • Re: FTP question
    ... I have two systems behind a firewall ... > up/download data. ... > checked the firewall settings on both machines). ... Probably the difference is active ftp vs. passive ftp. ...
    (comp.os.linux.security)
  • Re: FTP question
    ... >>> checked the firewall settings on both machines). ... >> Probably the difference is active ftp vs. passive ftp. ... FTP uses port 21 for the command channel. ...
    (comp.os.linux.security)