hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Hosting Security and Technology : Software Firewall for Win2003 server
Reply

Hosting Security and Technology Configuring and optimizing web hosting servers and operating systems, developing administration scripts, building servers, protecting against hackers, and general security (SSL certificates, etc.)
Forum Jump

Software Firewall for Win2003 server

Reply Post New Thread In Hosting Security and Technology Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 01-13-2004, 05:24 AM
COH_Henrik COH_Henrik is offline
Junior Guru Wannabe
 
Join Date: Nov 2003
Posts: 85

Software Firewall for Win2003 server


Hi,

We're looking for a software firewall to our Windows 2003 Standard Edition server.

Every server has approximatley 15 web sites with dedicated IP addresses.

I have considered to rent the SnapGear PCI630 from ServerMatrix, but it won't support that many IPs!

Best regards,
Henrik

Reply With Quote


Sponsored Links
  #2  
Old 01-13-2004, 07:05 AM
my_forum_id my_forum_id is offline
Aspiring Evangelist
 
Join Date: Oct 2002
Posts: 353
Have you checked out the built in RRAS support ?

( Under administrative tools ).

You can set up a basic firewall using this - it just blocks everything and you can pick the ports you want to open up to incoming connections.

It's very easy to set up and it has preconfigured values so if you want to allow say mail ftp web remote desktop on a server you just tick those 4 boxes and it will block all ports but those.

Best of all you can install it and choose NOT to start it straight away so you have a chance to set things up (especially remote desktop) before making it live so you don't lock yourself out of the server which seems to happen a lo with software firewalls.

Highly recommended.

Reply With Quote
  #3  
Old 01-13-2004, 07:19 AM
COH_Henrik COH_Henrik is offline
Junior Guru Wannabe
 
Join Date: Nov 2003
Posts: 85
Hi,

You mean the "Internet Connection Firewall"?

I got problem with it, my sistes stops running. I've opened all common ports!

If I get it to work I think there will be problems when I got customers that would lika dedicated IPs for there sites.

Best regards,
Henrik

Reply With Quote
Sponsored Links
  #4  
Old 01-13-2004, 07:31 AM
eddy2099 eddy2099 is offline
Web Hosting Master
 
Join Date: May 2001
Posts: 8,070
Thanks for the updates. I did not know there was a 15 IPs limit for the Snapgear card. I thought it had a higher limit.

Reply With Quote
  #5  
Old 01-13-2004, 07:34 AM
pmabraham pmabraham is offline
Web Hosting Master
 
Join Date: Dec 2001
Posts: 5,221
Greetings

Search the forums ;-)

http://www.webhostingtalk.com/showth...hreadid=223696

Thank you.

__________________
---
Peter M. Abraham
LinkedIn Profile


Reply With Quote
  #6  
Old 01-13-2004, 07:52 AM
cptkoi cptkoi is offline
WHT Addict
 
Join Date: Jul 2001
Location: UK
Posts: 137
BlackIce Server - every time

__________________
Koihost - Windows Solutions
http://www.koihost.com
--------
Quality usually costs more!

Reply With Quote
  #7  
Old 01-13-2004, 08:08 AM
COH_Henrik COH_Henrik is offline
Junior Guru Wannabe
 
Join Date: Nov 2003
Posts: 85
Quote:
Originally posted by eddy2099
Thanks for the updates. I did not know there was a 15 IPs limit for the Snapgear card. I thought it had a higher limit.
I don't know if the limit is 15 ips, but I'm waiting an answer from ServerMatrix. I asked them first about 20 IPs, but they didn't gave me the maximum number.

Reply With Quote
  #8  
Old 01-13-2004, 08:44 AM
my_forum_id my_forum_id is offline
Aspiring Evangelist
 
Join Date: Oct 2002
Posts: 353
Quote:
Originally posted by COH_Henrik
Hi,

You mean the "Internet Connection Firewall"?

I got problem with it, my sistes stops running. I've opened all common ports!

If I get it to work I think there will be problems when I got customers that would lika dedicated IPs for there sites.

Best regards,
Henrik
No, I mean RRAS - totally different package.

With RRAS you can set independent rules for each IP address, even each lan connection if you have more than one.

It's an absolute hidden gem in 2003 and I'm suprised MS don't make more effort to introduce people to it.

Click on Start -> Settings -> Control Panel -> Administrative tools and you'll see it listed (assuming you have w2003 standard - don't think it's in the web edition).

Reply With Quote
  #9  
Old 01-13-2004, 09:54 AM
COH_Henrik COH_Henrik is offline
Junior Guru Wannabe
 
Join Date: Nov 2003
Posts: 85
Thank you!

I think I found it under "Routing and Remote Access".

Now I got something called "NAT/Basic Firewall".

Here I find my network adapter.

Here is a tabb called "Address Pool" with description "Your Internet service provider (ISP) assigns this address pool". .

Should I put my IPs from ServerMatrix here?
Eg:
From: 69.93.xx.98
Mask: 255.255.255.248
To: 69.93.xx.102


Then I have a tab called "Services and ports"
It look like below:

--- Publilc address --------------------------
On this interface
On this address pool entry:

Incoming port: 21
Private address: 0.0.0.0
Outgoing port: 21

If I eg want port 21 to be open for my IPs 69.93.xx.98-69.93.xx.102. How should I configure it? 69.93.xx.98 is the main IP and the other are for new web hosting customers that need dedicated IPs for there sites.

Should I have my main IP entered under "private address? If I choose "On this interface" under public address, will all my public IPs work then?

Thank you in advance,
Henrik

Reply With Quote
  #10  
Old 01-13-2004, 10:17 AM
cprompt cprompt is offline
Aspiring Evangelist
 
Join Date: Nov 2003
Location: Olde Englandshire
Posts: 378
Quote:
Originally posted by COH_Henrik
Hi,

You mean the "Internet Connection Firewall"?

I got problem with it, my sistes stops running. I've opened all common ports!

The ICF only supports a single IP address per machine. It assumes that you have a single IP for your network and it enables you to redirect inbound traffic to servers on the network by port. You can not have multiple rules per IP.

I am trying the Routing and Remote Access firewall on my local W2K3 box before attempting it on my hosted server (I have already locked my self out twice )

Reply With Quote
  #11  
Old 01-13-2004, 10:29 AM
COH_Henrik COH_Henrik is offline
Junior Guru Wannabe
 
Join Date: Nov 2003
Posts: 85
I have now my "Routing and Remote Access firewall" to work pretty well. First I had problems that I could not connect to ftps and sites. I added port 53, but I it still didn't work, but when I also added port 53 with the UDP option it suddenly worked!

I haven't tried if it works with multiple external IPs yet..

Reply With Quote
  #12  
Old 01-13-2004, 11:08 AM
SoftWareRevue SoftWareRevue is online now
iNET Senior Community Advisor
 
Join Date: Jun 2001
Location: Kalamazoo
Posts: 31,239
Moved to the "Technical & Security Issues" Forum.

__________________
Do you have a WHT question or concern? Please open a helpdesk ticket.

Reply With Quote
  #13  
Old 01-13-2004, 01:12 PM
elementip elementip is offline
Junior Guru
 
Join Date: Apr 2003
Posts: 235
You could also set up TCP filtering, to block specific ports. It's not a full firewall solution, but it can go a long way towards securing a box.

Something with some sort of SPI would be better though.

__________________
-= System Administrator Windows/Linux - MCDST, MCP =-
www.VETCOELECTRONICS.com

Reply With Quote
  #14  
Old 01-13-2004, 07:57 PM
my_forum_id my_forum_id is offline
Aspiring Evangelist
 
Join Date: Oct 2002
Posts: 353
RRAS is TCP filtering with knobs on !

Reply With Quote
Reply

Related posts from TheWhir.com
Title Type Date Posted
GoGrid Adds New Firewall Services to Cloud SDN Architecture Web Hosting News 2013-04-11 10:50:21
Cloud Provider FiberCloud Offers Virtual Firewall Protection Web Hosting News 2012-05-08 12:15:24
CloudPassage Launches Network Security Solution for Multi-Cloud Environments Web Hosting News 2012-02-01 11:30:30
Web Hosting Sales and Promos Roundup - October 21, 2011 Web Hosting News 2011-10-21 21:21:38
PCI Compliance is About to Get Real, with Benny Crampton of LiquidWeb Web Hosting News 2011-10-12 22:31:27


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?