Re: port blocking on Windows 2000/2003 servers

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 11/23/04


Date: Tue, 23 Nov 2004 13:40:12 -0600

The Windows 2003 Security guide does exactly what you want and starts with a
baseline security configuration and goes from there with chapters based on
server role. It recommends the use of an ipsec "filtering" policy to secure
ports on servers. If you implement an ipsec "negotiation" policy be aware
that domain controllers must be exempt from the ipsec policy with domain
members by their IP address as they are the kerberos distribution centers or
else all kinds of problems can ensue. FYI I would not recommend applying
security templates to a production computer - be sure to test out first and
best practice would be to import them into a domain or Organizational Unit
Group Policy, other than default ones, to implement which will make it easy
to disable the GPO with the template. Ipsec policy can not be applied via a
security template. The Windows 2003 Security Guide is available at the link
below. Note that W2003 security templates will not be totally compatible
with W2K servers as many of the security options do not exist on W2K and
results will be unpredictable at best. Best practice would be to place the
different operating systems in different OU's and apply appropriate security
templates to each. --- Steve

http://www.microsoft.com/downloads/details.aspx?FamilyID=8a2643c1-0685-4d89-b655-521ea6c7b4db&displaylang=en
http://tinyurl.com/dkbu -- free download.

"Phil McNeill" <philmcneill@NOSPAM4MEhydroottawa.com> wrote in message
news:udzJRZX0EHA.632@TK2MSFTNGP10.phx.gbl...
> Hi,
>
> I am looking for recommendations on what would be the best thing to use to
> lock down all unneeded ports on Windows 2000 Server and Windows Server
> 2003 servers. Basically, we are looking at implementing policy that will
> have us not only ensuring all unneeded services are disabled, but ensuring
> some kind of packet filtering is in place on each individual server that
> will block all port access except those specifically defined as allowed.
> We will likely want to get as granular as specifying which servers/clients
> can talk to which other servers/clients.
>
> 1. How many other people out there are doing this, and how onerous of a
> task is it to implement/manage?
>
> 2. What's the best thing to be using to do it with? IPSEC policies, or
> do I want some kind of software firewalls on each server?
>
> Thanks for any and all tips/advice.
>
> Phil
>



Relevant Pages

  • SecurityFocus Microsoft Newsletter #164
    ... Got Storage Security Risks? ... MICROSOFT VULNERABILITY SUMMARY ... Chat Client FTP Server Default Username Credential Weak... ... NetServe Web Server is a compact web server for Microsoft Windows ...
    (Focus-Microsoft)
  • RE: Cant set Local Security policies. They fail to save
    ... predefined Security Template on SBS 2003 to restore security groups ... run "gpupdate.exe /force" under command prompt to force the policy ... reboot the Server to test. ... and then logon to client computer to test if user can save system logs. ...
    (microsoft.public.windows.server.sbs)
  • Re: im being held in memory
    ... How can I harden my computer or server to secure it from hackers? ... Use firewall software and hardware and antivirus software that is ... Follow the instructions for hardening Windows and IIS at ... Install all service packs and security fixes from Microsoft and otherwise ...
    (microsoft.public.security)
  • MS and security: good effort but no cigar
    ... build upon the progress it's already made in security. ... The low-hanging fruit of millions of insecure Windows machines ... Then there's the issue of poorly secured server applications. ... and execute external virus and filtering ...
    (microsoft.public.windowsxp.general)
  • SecurityFocus Microsoft Newsletter #167
    ... MICROSOFT VULNERABILITY SUMMARY ... Multiple Vendor XML Parser SOAP Server Denial Of Service Vul... ... Proactive Windows Security Explorer ...
    (Focus-Microsoft)