W2K TCP/IP Filtering

From: Steve (anonymous_at_discussions.microsoft.com)
Date: 08/28/04


Date: Sat, 28 Aug 2004 09:54:16 -0700

I have a new w2k web server getting ready to go online,
and I'm having some problems with the tcp/ip filtering.
Following the guide at http://www.shebeen.com/w2k/ for
basic hardening, I've enabled TCP/IP filtering. Problem
is that it seems to break the connection to our DNS
servers (internet DNS servers with IPs specified in the
TCP/IP address properties). When I disable the TCP/IP
filtering, everything works as it should.

The settings are: TCP Permit only 22,80,443,3389
UDP permit only: 161,162
Protocols: 6,8

I know if I was running DNS on this machine, I'd need 53
open, but I'm not sure why the filtering is blocking name
resolution when connecting to an outside dns server.



Relevant Pages

  • RE: TCP/IP Filtering problem on W2KAS
    ... The problem is that if you are listing ports that are 'allowed' and you ... don't list every dynamic port used by a client to access the DNS ... "Using IPSec to Lock Down a Server": ... I find using the IPSec filters MUCH more useful then the TCP/IP Filtering. ...
    (Focus-Microsoft)
  • TCP/IP Filtering problem on W2KAS
    ... I've enabled TCP/IP filtering on a W2KAS IIS server. ... conversation with a dns server and receive an answer. ...
    (Focus-Microsoft)
  • TCP/IP Filtering works for incomming traffic, but closed my outgoing traffic
    ... TCP/IP Filtering works for incomming traffic, ... I have enabled the TCP/IP Filtering on my Windows 2000 Server, ... Internet from within the server. ... to the Enabled ports to be able to access the internet or what should I do? ...
    (microsoft.public.windows.server.security)
  • Re: Blocking SQL server by machine name?
    ... Using TCP/IP Filtering is not an option because of DHCP server. ... MAC address but that way that user may not use all the apps in the server. ... Now I know that a person shouldn't be access to the SQL box ... > used account and implement Windows Authentication with nt group membership. ...
    (microsoft.public.sqlserver.security)
  • Re: Forward lookup zone not automatically created for new domain i
    ... I updated the 'Preferred DNS server' on shell.company to ... Did you remove the other DNS servers? ... This looks like you already had replication errors (at least ... No forward lookup zone appeared. ...
    (microsoft.public.windows.server.active_directory)