Re: IP security policy: blocking access

From: x y (jamescagney90210@excite.com)
Date: 07/16/02


From: "x y" <jamescagney90210@excite.com>
Date: Tue, 16 Jul 2002 07:26:20 -0400


Windows 2000 IPsec packet filtering does not have logging, which is
absolutely essential. You need a firewall software or hardware that logs
blocked packets, so you can 1) troubleshoot problems and 2) detect
intrusions. Sygate firewall is a free or inexpensive way to do this. Note
that any software solution for blocking packets, including IPsec, can
theoretically be bypassed or disabled by malicious code like trojans.

"Pat" <nobody@nowhere.com> wrote in message
news:uOITw6$KCHA.1608@tkmsftngp09...
> I am trying to block access to a FTP server in the DMZ. No other server in
> the DMZ should be able to access this specific server. On the other hand,
> this server should be able to access all the other servers in the DMZ.
>
> If I deny access for all other servers (source: DMZ subnet, destination:
my
> IP, deny), the FTP server can't access the others, either (ping, ftp
etc.)?
> What am I missing?
>
>



Relevant Pages

  • Re: How to establish connections to the servers inside a DMZ?
    ... Each server is assigned one of those IPs. ... >> (inside the DMZ) is accessed. ... >Directing packets to the dmz is accomplished with route table entries. ... >packets) and use connection tracking and ESTABLIHED, ...
    (comp.os.linux.networking)
  • Re: DMZ vs ISA 2004 ?
    ... ISA is a Firewall software and a DMZ is a concept. ... > for a web server or for an exchange server. ...
    (microsoft.public.isaserver)
  • RE: fedora-list Digest, Vol 6, Issue 266
    ... Re: OT: Setting up a forwarding mail domain in DMZ without ... Re: Sound Problem ... downloaded the yum.conf for fedora from Redhat's website. ... Server: Fedora.us Extras ...
    (Fedora)
  • RE: Webserver on a DMZ still needed?
    ... Certainly your suggestion to have a email server in a DMZ but still have ... having the exchange server on the internal LAN with only the smtp ports ... Talking of the financial cost of setup by the book vs the security cost ...
    (Security-Basics)
  • Re: Diagnose co-location networking problem
    ... it was from the client. ... Actually there's significant indication of lost packets and clues that ... 540 retransmit timeouts ... are you using any packetfiltering on the server? ...
    (freebsd-net)

Loading