Solved

Blocking ports on windows 2000 advanced server

Posted on 2003-10-28
7
1,495 Views
Last Modified: 2010-04-14
I want to block only one tcpip port on a server located outside firewall, how do I go about that?
0
Comment
Question by:leguino
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
7 Comments
 
LVL 43

Accepted Solution

by:
JFrederick29 earned 84 total points
ID: 9635027
In your LAN connection properties, double click TCP/IP then click the advanced button.  Click the "options" tab then double click "TCP/IP filtering".  Check the "Enable TCP/IP Filtering (All adapters) button.  Next, add the ports that are permitted to access the server.  The rest will be blocked.

You could also use third party firewall software to block the one port in question.
0
 
LVL 10

Assisted Solution

by:KingHollis
KingHollis earned 83 total points
ID: 9635067
If this server is located outside of your firewall, it must have a specific purpose. Determine the ports needed then go to the Advanced TCP/IP settings for that NIC and choose to Allow only the TCP or UDP ports you require. All others will then be restricted. For example, if this is your webserver, people will only need to access TCP/80 and poss'y TCP/443. Don't try to block just one port-- make the server a true bastion host and reduce the attack surface.
0
 
LVL 1

Assisted Solution

by:Dave3131
Dave3131 earned 83 total points
ID: 9663643
IPSec policy works well for blocking a single port.   Here is the MS Technet article on using IPSec Policy to lock down a server:
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/itsolutions/network/maintain/security/ipsecld.asp

You can use the basics in that article to shut off any port you want.   I agree with KingHollis that you should lock down all the ports you are not using.  The article tells how to do this effectively.
0
 
LVL 43

Expert Comment

by:JFrederick29
ID: 10043604
leguino

If we helped at all, please split the points between the three of us.  If not, request a refund.
0

Featured Post

On Demand Webinar - Networking for the Cloud Era

This webinar discusses:
-Common barriers companies experience when moving to the cloud
-How SD-WAN changes the way we look at networks
-Best practices customers should employ moving forward with cloud migration
-What happens behind the scenes of SteelConnect’s one-click button

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
Originally, this post was published on Monitis Blog, you can check it here . Websites are getting bigger and more complicated by the day. Video, images and custom fonts are all great for showcasing your product or service. But the price to pay in…
Finds all prime numbers in a range requested and places them in a public primes() array. I've demostrated a template size of 30 (2 * 3 * 5) but larger templates can be built such 210  (2 * 3 * 5 * 7) or 2310  (2 * 3 * 5 * 7 * 11). The larger templa…
How to Install VMware Tools in Red Hat Enterprise Linux 6.4 (RHEL 6.4) Step-by-Step Tutorial

733 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question