port blocking on Windows 2000/2003 servers

From: Phil McNeill (philmcneill_at_NOSPAM4MEhydroottawa.com)
Date: 11/23/04


Date: Tue, 23 Nov 2004 11:05:52 -0500

Hi,

I am looking for recommendations on what would be the best thing to use to
lock down all unneeded ports on Windows 2000 Server and Windows Server 2003
servers. Basically, we are looking at implementing policy that will have us
not only ensuring all unneeded services are disabled, but ensuring some kind
of packet filtering is in place on each individual server that will block
all port access except those specifically defined as allowed. We will
likely want to get as granular as specifying which servers/clients can talk
to which other servers/clients.

1. How many other people out there are doing this, and how onerous of a
task is it to implement/manage?

2. What's the best thing to be using to do it with? IPSEC policies, or do
I want some kind of software firewalls on each server?

Thanks for any and all tips/advice.

Phil



Relevant Pages

  • Re: how to find "step by step" articles to learn windows 2003 AD?
    ... Sites by Using ISA Server in Windows 2000 and Windows 2003" ... Additional Help Files for Windows Server 2003" ... http://support.microsoft.com?kbid=323360 "How to install and configure a DHCP ... http://support.microsoft.com?kbid=323381 "HOW TO Allow Remote Users to Access ...
    (microsoft.public.win2000.advanced_server)
  • Re: Installation Failure - Error Code 0x80244018
    ... You experience problems when you access the Windows Update Version 6 Web site through a server that is running ISA Server ... .101 is pruned out due to potential supersedence ... [CallerId = MicrosoftUpdate] ...
    (microsoft.public.windowsupdate)
  • RE: Backups, VSS and SBS2003 HELP NEEDED!!!
    ... suggest customers Only install Windows Server 2003 SP1 on their server. ...
    (microsoft.public.windows.server.sbs)
  • Der Server konnte keinen nicht ausgelagerten Poolspeicher reservieren, da
    ... Der Server konnte keinen ausgelagerten Poolspeicher reservieren, ... Product Name Microsoft Windows Server 2003 R2 Build Lab ... Sicherheitsupdate für Windows Internet Explorer 7 1 ...
    (microsoft.public.de.german.windows.server.general)
  • Re: SBS 2008 becomes slow a few days after restart
    ... > originally the server was SBS2000 with no such problems. ... Most drivers are Microsoft original. ... Information about the TCP Chimney Offload, Receive Side Scaling, and Network Direct Memory Access features in Windows Server 2008 ... That's why i asked about "Opportunisting Locking" AND "active directory", because one is file/share related, the other is a database connection (Active Directory is a LDAP-Database where data is pulled from LDAP-clients via LDAP-Connections on TCP-Port 389 - s. ...
    (microsoft.public.windows.server.sbs)