Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

How Block IP traffic on  Exchange 2000 except for needed 25 80?

Posted on 2003-11-12
4
Medium Priority
?
376 Views
Last Modified: 2013-12-04
The Exchange Server is behind a NAT and all I care about is Auto Critical update traffic and SMTP25 and OWA80.

Using a new Linksys BEFVPN41 in Gateway mode. LAN is 10.10.10x.
Wish the linksys had inbound port blocking not just outbound.

I'm seeing outbound traffic to odd ports 33975 57405 and odd IP destinations, I believe spoofed.
Un-used blocks in China, or a bank in Amsterdam. We're in IL USA.

So I want to block all non exchange WAN traffic, except windows auto critical update, and NetShield and Groupshield getting FTP Dat updates.

LANly it is also a W2kAdvSvr DHCP, DNS, AD, and user file storage/sharing.

I know a little about using policies or Rules in RRAS.

I'm looking for somebody that has already locked down his or her Exchange server using policies and or RRAS and can pass on their sweat.

It's for a small non-profit company and I'm only part time for them, and they have a memory problem causing system reboots, keeping me to busy tracking down with poolmon and it is a pain. I'm currently looking at SNMP process handle count steadily climbs 1650 every 5 seconds till service is restarted I don't know if that is normal or not. Was over 400k handles yesterday. The only dependant for the Service is the eventlog. I got to keep searching. I guess it will be another EE collaboration.

I don't want their system being hacked, used as a zombie or pass-through like in old book "The CooCoo's Egg".

Thanks very much in Advance.
0
Comment
Question by:Suburb-Man
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 32

Assisted Solution

by:LucF
LucF earned 400 total points
ID: 9737765
>I'm seeing outbound traffic to odd ports 33975 57405 and odd IP destinations, I believe spoofed.
I suggest you first run a spyware checker and a virusscan on that server.

Spyware/Adware removal tools:
------------------------------
SpyBot-S&D : http://www.webattack.com/download/dlspybot.shtml 
Ad-aware : http://www.webattack.com/download/dladaware.shtml 
Trojan Remover :http://www.simplysup.com/
HijackThis : http://www.webattack.com/download/dlhijackthis.shtml 
KL-Detector  :http://www.webattack.com/download/dlkldetector.shtml
X-Cleaner Free  :http://www.webattack.com/download/dlxcleaner.shtml
SpywareBlaster  :http://www.webattack.com/download/dlspywareblaster.shtml
SpywareGuard :http://www.webattack.com/download/dlspywareguard.shtml

Online virus checker
------------------------------
Trend Micro HouseCall : http://housecall.antivirus.com/housecall/start_corp.asp
PC Pitstop Virus Scan : http://www.pcpitstop.com/antivirus/default.asp 

LucF
0
 
LVL 5

Accepted Solution

by:
juliancrawford earned 1600 total points
ID: 9740268
if you want to stop the traffic just use ipsec policy and stop it at the scket.
http://www.microsoft.com/serviceproviders/columns/using_ipsec.asp
0
 
LVL 1

Author Comment

by:Suburb-Man
ID: 9750440
Thanks for the prompt responses.

Thanks for Spyware/Adware removal tools links, I’m sorry I didn’t mention that Spybot S&D is installed and that NetShield and GroupShield are NAI-McAfee anti-virus utilities. Both run in the background all the time and do a full scan every night.
All are set to auto retrieve updates/upgrades.

Thanks I forgot about the IPsec blocking at the socket level, and the great link.
This will most defiantly get me well on my way.

Also I did find a nice collaboration about IDS:
http://www.experts-exchange.com/Security/Q_20788052.html

Of course I ideally wanted someone to share with me exactly how and what they did to lock down their Exchange Server.

So 20%-80% point split.
20% because it is always good to look at the possible causes.
80% because it is closest to the answer I wanted, with an A grade.
0
 
LVL 32

Expert Comment

by:LucF
ID: 9750770
ThanQ
0

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In a recent article here at Experts Exchange (http://www.experts-exchange.com/articles/18880/PaperPort-14-in-Windows-10-A-First-Look.html), I discussed my nine-month sandbox testing of the Windows 10 Technical Preview, specifically with respect to r…
OfficeMate Freezes on login or does not load after login credentials are input.
Have you created a query with information for a calendar? ... and then, abra-cadabra, the calendar is done?! I am going to show you how to make that happen. Visualize your data!  ... really see it To use the code to create a calendar from a q…
Is your data getting by on basic protection measures? In today’s climate of debilitating malware and ransomware—like WannaCry—that may not be enough. You need to establish more than basics, like a recovery plan that protects both data and endpoints.…
Suggested Courses

636 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question