Re: IP Sec

From: Herb Martin (news_at_LearnQuick.com)
Date: 09/27/03


Date: Sat, 27 Sep 2003 10:04:09 -0500


> ///
> ipsecpol -dialup -w REG -p "Web" -o
> ipsecpol -dialup -x -w REG -p "Web" -r "BlockAll" -n BLOCK -f 0+*
> ipsecpol -dialup -x -w REG -p "Web" -r "OkHTTP" -n PASS -f 0:80+*::TCP
> \\\
>
> This should secure a server, so that only port 80 is open. Well, that
> works - but it also applies to outgoing connections, which I don't want.
> Could anyone tell me how to modify those lines, so that only incoming
> connections are affected? And could anyone tell me how I can securely
> "delete" that settings with ipsecpol (if I press 'Del' in the IP Sec
> MMC, there keep remnants in the registry).

You will just need to PASS the (more) specific traffic you wish to allow,
e.g.,
outgoing FTP or whatever.

-- 
Herb Martin


Relevant Pages

  • Re: Created on Access 2003, but.......................
    ... But that's not secure under any scenario, as any port scanner ... Well, you still need a userid, password and database name. ... You're assuming the server remains in a secured configuration. ...
    (comp.databases.ms-access)
  • Re: 553 sorry, relaying denied from your location
    ... connection on port 465. ... Newly created server is on port 465, ... iterations of secure, always secure, 128 bit encryption, etc. ... that doesn't appear to be an Exchange response. ...
    (microsoft.public.exchange.setup)
  • RE: Lotus Notes - Is this a bad thing?
    ... > Make sure you have your firewall set up right... ... Remember that something secure today may not be tomorrow so, ... Try cutting UDP access to the server completely, ... Make sure port encryption is enabled on the servers ...
    (Security-Basics)
  • Re: Terminal server and http
    ... The easiest and most secure way to do this is to drop in a SSL VPN device ... client being able to communicate over port 3389. ... Of course you cannot use an IP address where you also have a Web Server ... This action depends on the firewall you're using. ...
    (microsoft.public.windows.terminal_services)
  • Re: VPN Windows 2000
    ... Just to throw my 2 cents worth here, PPTP is not nearly as secure as ... data stream or a publicly available server. ... I have personnaly used port forwarding for PPTP to access my ...
    (microsoft.public.win2000.networking)