Re: About utility of a firewall with win2000 server

From: Jeff Cochran (jcochran)
Date: 09/03/02


From: jcochran at naplesgov dot com (Jeff Cochran)
Date: Tue, 03 Sep 2002 17:38:27 GMT


>Everybody says : "You must install a firewall" . I'm of course ready to do
>it but I don't really understand why...?

Are you *absolutely* sure you can close every possible opening in your
server?

>For me, the utility of a firewall is clear when a PC has a gateway function
>but is it the case for a server exclusively used for web server tasks ?

The firewall can detect many more attack types than a server can.
Plus it can drop all attacks before the server has to spend time
dealing with them. A sinmple denial of service will stop your server
dead, but be dropped by a firewall.

>What's the rule in NT-2000 ?

No rules. Just educated administrators. :)

>All the ports are opened as soon as an IP adress is affected ?
>All the ports are closed exepted those opened while configuring webservices
>?

In NT/2000, everything is open by default. Check
http://www.microsoft.com/security/ for good guidelines.

Jeff



Relevant Pages

  • Re: Interesting webserver intrusion (apache 1.3.31, mod_ssl 2.8.18, php 4.3.7)
    ... > fairly tight(only allowing 4 ports in), but perhaps I could tighten it ... The host systems firewall rules govern the access to the jailed system. ... What connections does your server need to ... Perhaps there is a 0-day for your ftp server out there. ...
    (Incidents)
  • Re: CEICW fails at firewall config
    ... Do you or do you not have ISA 2000 or ISA 2004 installed on the SBS server? ... Do you have 2 NICs in the SBS? ... CEICW fails on firewall configuration every time. ... >>> Call to Creating the protected networks access rule returned ok. ...
    (microsoft.public.windows.server.sbs)
  • Re: Add 2nd NIC after intial install?
    ... My biggest question with 1 NIC is: even if workstations are protected with individual firewall products, what is protecting the SBS server itself if ports are open for remote access through the Linksys firewall? ...
    (microsoft.public.windows.server.sbs)
  • Re: Recycler security issues on IIS server
    ... > latest upates to the server. ... > like to see the server put behind our firewall, ... other software, install all patches, IISlockdown, URLscan, use the correct ... the procedures you follow may vary depending on your security needs. ...
    (microsoft.public.inetserver.iis.security)
  • Re: Source Code to Filter out WindowsMessenger POP-UPS
    ... Zone Alarm does NOT support 'server'. ... Very few ports are open, ... >What you are asking for amounts to a firewall. ... I would NOT search for source code to compile ...
    (microsoft.public.inetserver.iis.security)