port blocking on Windows 2000/2003 servers

From: Phil McNeill (philmcneill_at_NOSPAM4MEhydroottawa.com)
Date: 11/23/04


Date: Tue, 23 Nov 2004 11:05:52 -0500

Hi,

I am looking for recommendations on what would be the best thing to use to
lock down all unneeded ports on Windows 2000 Server and Windows Server 2003
servers. Basically, we are looking at implementing policy that will have us
not only ensuring all unneeded services are disabled, but ensuring some kind
of packet filtering is in place on each individual server that will block
all port access except those specifically defined as allowed. We will
likely want to get as granular as specifying which servers/clients can talk
to which other servers/clients.

1. How many other people out there are doing this, and how onerous of a
task is it to implement/manage?

2. What's the best thing to be using to do it with? IPSEC policies, or do
I want some kind of software firewalls on each server?

Thanks for any and all tips/advice.

Phil



Relevant Pages

  • Re: how to find "step by step" articles to learn windows 2003 AD?
    ... Sites by Using ISA Server in Windows 2000 and Windows 2003" ... Additional Help Files for Windows Server 2003" ... http://support.microsoft.com?kbid=323360 "How to install and configure a DHCP ... http://support.microsoft.com?kbid=323381 "HOW TO Allow Remote Users to Access ...
    (microsoft.public.win2000.advanced_server)
  • RE: Backups, VSS and SBS2003 HELP NEEDED!!!
    ... suggest customers Only install Windows Server 2003 SP1 on their server. ...
    (microsoft.public.windows.server.sbs)
  • [NT] Vulnerabilities in DNS Allows Spoofing (MS08-037)
    ... Get your security news from a reliable source. ... the Windows Domain Name System (DNS) that could allow spoofing. ... Microsoft Windows 2000, Windows XP, Windows Server 2003, and Windows ...
    (Securiteam)
  • RE: W32Time Event ID 29
    ... obtain the latest service pack for Windows Server ... Microsoft CSS Online Newsgroup Support ... This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)
  • Re: sbs2003 sp1 - cannot browse /remote, /monitoring, /outlook
    ... Internally, logged on to the server as an administrator, when I run Server ... > that is running Windows Server 2003, run the Suptools.msi program that is ... > please visit the following Microsoft Web site: ... > ISA rules and then run CEICW to try to test. ...
    (microsoft.public.windows.server.sbs)