Hmm...

W2K have intrinsic basic 'firewall' fonctionnalities to block or accept =
ANY
protocol and PORTS you want without ANY add-in add-on !!

Three options to do that (I prefer last, as rras make network =
connexions
esaier to manage)
- option 1 : goto tcp/ip setting, select options tabs, click tcp/ip
filtering, click properties and enter authorised protos
(here you have to know ALL protocols to pass in advance ...)

- option 2 : using ip/sec features to control traffic (you don't really =
use
ipsec but can filter traffic with its rules (don't remember microsoft =
kb
article to do this, but i know its works, tested in labs ...)

- option 3 : 'BETTER' solution : install Routing and RAS (included in
windows 2k server) (minimum the routing part)
To install routing and ras, launch 'Routing and Remote access' console
manager from administrative tools
Select your server, right clic it and select 'install/configure rras'
Choose 'routing' only
When it become installed and running, in the rras mmc console, go to
'General' in 'IP routing', you will see your connexions
Right click the internet connexion
In the 'General' tab you have two button : Input filters and Output =
filters
Select if you want 'allow all except' or 'deny all except' (it is here =
the
'basic' functionnality, you just can't mix allow and deny, but if you =
put
good rules here, you have a perfect firewall at final setup!!)

Even if i currently have a separate firewall running, i allway used =
this
feature to protect my exposed w2k systems (do you fully trust you =
firewall ?
is your firewall allways secure ? or don't have bugs ...)

Francis


-----Message d'origine-----
De : Tracy [mailto:[EMAIL PROTECTED]
Envoy=E9 : vendredi 26 septembre 2003 16:40
=C0 : [EMAIL PROTECTED]
Objet : [xmail] Re: question about RDNS


It does reduce it, but it doesn't stop it altogether... It's very =
pervasive=20
in the OS....

At 10:41 9/26/2003, Davide Libenzi wrote:


>On Fri, 26 Sep 2003, Tracy wrote:
>
> > To close NetBIOS access, you need a hardwre or software firewall =
that
can
> > block the packets. You'll never be able to rip it out of Windows=20
> directly...
>
>IIRC, if you go in the network connection properties, advanced TCP/IP
>propeties, WINS, and then Disable NETBIOS over TCP/IP should fix it. =
Isn't
>it ?
>
>
>
>- Davide
>
>-
>To unsubscribe from this list: send the line "unsubscribe xmail" in
>the body of a message to [EMAIL PROTECTED]
>For general help: send the line "help" in the body of a message to
>[EMAIL PROTECTED]


-
To unsubscribe from this list: send the line "unsubscribe xmail" in
the body of a message to [EMAIL PROTECTED]
For general help: send the line "help" in the body of a message to
[EMAIL PROTECTED]
-
To unsubscribe from this list: send the line "unsubscribe xmail" in
the body of a message to [EMAIL PROTECTED]
For general help: send the line "help" in the body of a message to
[EMAIL PROTECTED]

Reply via email to