Re: Setup firewall using W2K IPSec MMC snap-in?
From: Karl Levinson [x y] mvp (levinson_k@excite.com)
Date: 03/26/03
- Previous message: Karl Levinson [x y] mvp: "Re: Disabling 8.3 Filename Creations on Win2k Server`"
- In reply to: HuntBchGuy: "Setup firewall using W2K IPSec MMC snap-in?"
- Next in thread: HuntBchGuy: "Re: Setup firewall using W2K IPSec MMC snap-in?"
- Reply: HuntBchGuy: "Re: Setup firewall using W2K IPSec MMC snap-in?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: "Karl Levinson [x y] mvp" <levinson_k@excite.com> Date: Wed, 26 Mar 2003 00:02:57 -0500
FWIW, IMHO IPSec in Win2K makes a poor firewall replacement. You have no
logging, no alerting, no way to research hacking incidents or know who
hacked you or who is using up your bandwidth, etc. I think of IPsec as
something to use MAYBE in addition to a real firewall. Some free and
not-free alternatives:
http://securityadmin.info/faq.htm#firewall
"HuntBchGuy" <huntbchguy@hotmail.com> wrote in message
news:xE0ga.15289$hz3.882@fe06.atl2.webusenet.com...
> Hello,
>
> I've installed the IPSec MMC snap-in and am trying to get a firewall
going.
>
> I've defined a firewall security policy with a few security rules and
> assigned it.
>
> For my local LAN I allow all ICMP traffic but have one Block rule and one
> Permit rule for IP traffic.
>
> My block rule blocks all TCP traffic and my permit rule permits traffic
only
> on the ports I've specified in a filter list.
>
> Will this work?
> Am I correct to assume that blocking all ports in one rule and permitting
> ports in another rule will allow access to permitted ports?
>
> The problem I'm seeing is that if I disable my block and permit rules, all
> ports are permitted (ie. accessible).
> If I just enable my block rule, all ports are blocked.
> If I enable my permit rule and my block rule, all ports are block.
>
> Any ideas on what I'm doing wrong?
>
> Thanks,
>
> -Randy
>
>
> --
> "Trying is just the first step to failure."
>
>
>
- Previous message: Karl Levinson [x y] mvp: "Re: Disabling 8.3 Filename Creations on Win2k Server`"
- In reply to: HuntBchGuy: "Setup firewall using W2K IPSec MMC snap-in?"
- Next in thread: HuntBchGuy: "Re: Setup firewall using W2K IPSec MMC snap-in?"
- Reply: HuntBchGuy: "Re: Setup firewall using W2K IPSec MMC snap-in?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|