About utility of a firewall with win2000 server

From: Jean-Paul Bihin (jean-paul.bihin@easynet.be)
Date: 09/03/02


From: "Jean-Paul Bihin" <jean-paul.bihin@easynet.be>
Date: Tue, 3 Sep 2002 08:25:58 +0200


Hi,
I'm configuring a webserver (win2000 server). His destination is a
datacenter.

It will be used exclusively for web services (http and ftp). Some ports will
of course be opened on each webfolder. The machine will have is own IP
adress (for remote control) and each Webfolder as well.
The access to all the other folders will be limited with NT-2000
administration tools.

Everybody says : "You must install a firewall" . I'm of course ready to do
it but I don't really understand why...?
For me, the utility of a firewall is clear when a PC has a gateway function
but is it the case for a server exclusively used for web server tasks ?

What's the rule in NT-2000 ?
All the ports are opened as soon as an IP adress is affected ?
All the ports are closed exepted those opened while configuring webservices
?

Thanks,

Jean-Paul

Bonjour,

Je configure un serveur Web sous Win2000 Server qui est destiné à être logé
dans un datacenter .
Il ne servira qu'à cela. Les ports ouverts seront limités à ceux que je
voudrai bien ouvrir sur chaque dossier "Web" ou "FTP" et chaque dossier Web
aura son adresse IP tout comme la machine elle-même bien sûr. Tous les
autres dossiers seront verrouillés par le système d'administration 2000-NT.
Tout le monde me dit "il faut un firewall" et je m'interroge...
Je crois bien comprendre l'utité d'un firewall dans le cas d'un serveur qui
fait "passerelle" ou qui fait du partage de connexion Internet mais QUID
dans ce cas ?
Est-ce que je ne peux pas faire aussi bien en utilisant toutes les
fonctionnalités de mon OS ?

Merci pour vos éclairages avisés...

Jean-Paul



Relevant Pages

  • Re: passiver FTP auf windows server 2003
    ... aber nur bestimte Ports per TCP/IP ... Dies ist dann das Problem beim passiven FTP. ... Ich hoffe Du hast noch sowas wie eine Firewall vor dem Server stehen, ...
    (microsoft.public.de.german.windows.server.setup)
  • Re: FTP server behind NAT using Kerio
    ... > I have a Windows 2000 FTP server running behind a Linksys DSL router. ... it is ftp at work. ... > Can I open up a range of outgoing ports for IIS? ...
    (comp.security.firewalls)
  • Re: ServU-deamon trojan warning with McAfee
    ... FTP FTP FTP. ... You did it to yourself by having FTP server on your SBS box without the ... > software didn't pick up this infection altough the DAT file included the ... > document what ports need to be opened and for what reason? ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: FTP Server Question
    ... >>understand why the server doesn't work when I disable UDP on the ports ... >>that you need both tcp and udp enabled and I've seen information that FTP ... I'm using non-standard ports with my server. ...
    (comp.security.firewalls)
  • Re: Windows Media Server deployment
    ... >Server is in datacenter so we don?t need firewall on every machine. ... >We tested ports with www.grc.com shields up and there is definitely firewall ... Well I'd start by asking the datacenter hosting to allow through your ...
    (microsoft.public.windowsmedia.server)