Some of the main things to do to secure the main node:
1) Use IPSec firewall to block all the unnecessary ports from the main node.
2) Apply Microsoft Hotfixes to the service VPS
http://www.microsoft.com/technet/sec.../MS03-031.mspx
http://support.microsoft.com/?kbid=815495
http://www.microsoft.com/downloads/d...displaylang=en
3) Disable TCP/IP networking is service VPS
4) Use private IP address for the service VPS
5) Use windows firewall to block all the ports except the following inside the service VPS
22, 139, 445, 4643, 3141, 3389, 8049
6) Very Important: Block the port 1433 inside SVE.