Solved

Securing FTP Site using VPN

Posted on 2006-07-12
6
285 Views
Last Modified: 2010-04-11
Hi,

I have sbs2003 with an ftp site. I have hardened ACL, have password authentication, configured lockout policy, etc...everything that can be done to block outside ftp users trying to crack password.

The only thing I have not done is deny access to everyone accept valid IP addresses. However, before I implement that I wanted to explore some reasons why I continue to see session even after an ip is blocked. Also, events continue to be logged in System and Security from that same ip address. Any thoughts?

Also, how can I implement FTP Site using VPN.

Thanks,
Mr. B
0
Comment
Question by:birenshukla
  • 3
  • 2
6 Comments
 
LVL 32

Expert Comment

by:r-k
ID: 17097521
"However, before I implement that I wanted to explore some reasons why I continue to see session even after an ip is blocked. Also, events continue to be logged in System and Security from that same ip address."

How did you lock out that IP?

The way to do it is via IIS Manager -> Right-click on FTP site -> Properties -> Directory Security, and add that IP address so it is blocked, etc.

0
 

Author Comment

by:birenshukla
ID: 17099341
that is exactly how i blocked the ip. I have other ipc blocked as well and they do not show.
0
 
LVL 4

Accepted Solution

by:
kruptos earned 500 total points
ID: 17158645
It may be possible that someone may be spoofing IP. It may look like it is coming from the blocked IP but you can mask the IP with a fake one. This will allow the spoofed IP to be logged but the real one to get through. Not sure if that is the case here though.

What is the FTP site being used for? Internal employees? Customers? That will help us determin the best way to deploy a VPN solution.

-Kruptos
0
How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

 

Author Comment

by:birenshukla
ID: 17158724
FTP site is strictly for selected customers. I have explored options to deny to everyone except the public IP addresses but that is alwasys hard to get from customers and would need continuous maintenance. Therefore the VPN option. I would say at the most 5 customers connect from time to time.
0
 
LVL 4

Expert Comment

by:kruptos
ID: 17158761
You could set up a VPN that will only allow access directly to the server that is acting as FTP. It really depends on what type of firewall you have and it capabilities.

Depending on how secure you want to get will determin the architecture. Personally I woud never run FTP and IIS on SBS if that is your only server. Do you have other servers as well or just the SBS server?

If youc an let me know what type of firewall you have running I may be able to give you some ideas on how to set up the VPN for FTP access.

-Kruptos
0
 

Author Comment

by:birenshukla
ID: 17292213
Thanks. Will try that. I have been continuoing to deny bad guys but that is about it. I am going to get a industry grade firewall.
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Suggested Solutions

Password hashing is better than message digests or encryption, and you should be using it instead of message digests or encryption.  Find out why and how in this article, which supplements the original article on PHP Client Registration, Login, Logo…
If you're not part of the solution, you're part of the problem.   Tips on how to secure IoT devices, even the dumbest ones, so they can't be used as part of a DDoS botnet.  Use PRTG Network Monitor as one of the building blocks, to detect unusual…
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
This video shows how to remove a single email address from the Outlook 2010 Auto Suggestion memory. NOTE: For Outlook 2016 and 2013 perform the exact same steps. Open a new email: Click the New email button in Outlook. Start typing the address: …

760 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now