Solved

Securing FTP Site using VPN

Posted on 2006-07-12
6
292 Views
Last Modified: 2010-04-11
Hi,

I have sbs2003 with an ftp site. I have hardened ACL, have password authentication, configured lockout policy, etc...everything that can be done to block outside ftp users trying to crack password.

The only thing I have not done is deny access to everyone accept valid IP addresses. However, before I implement that I wanted to explore some reasons why I continue to see session even after an ip is blocked. Also, events continue to be logged in System and Security from that same ip address. Any thoughts?

Also, how can I implement FTP Site using VPN.

Thanks,
Mr. B
0
Comment
Question by:birenshukla
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
6 Comments
 
LVL 32

Expert Comment

by:r-k
ID: 17097521
"However, before I implement that I wanted to explore some reasons why I continue to see session even after an ip is blocked. Also, events continue to be logged in System and Security from that same ip address."

How did you lock out that IP?

The way to do it is via IIS Manager -> Right-click on FTP site -> Properties -> Directory Security, and add that IP address so it is blocked, etc.

0
 

Author Comment

by:birenshukla
ID: 17099341
that is exactly how i blocked the ip. I have other ipc blocked as well and they do not show.
0
 
LVL 4

Accepted Solution

by:
kruptos earned 500 total points
ID: 17158645
It may be possible that someone may be spoofing IP. It may look like it is coming from the blocked IP but you can mask the IP with a fake one. This will allow the spoofed IP to be logged but the real one to get through. Not sure if that is the case here though.

What is the FTP site being used for? Internal employees? Customers? That will help us determin the best way to deploy a VPN solution.

-Kruptos
0
Transaction Monitoring Vs. Real User Monitoring

Synthetic Transaction Monitoring Vs. Real User Monitoring: When To Use Each Approach? In this article, we will discuss two major monitoring approaches: Synthetic Transaction and Real User Monitoring.

 

Author Comment

by:birenshukla
ID: 17158724
FTP site is strictly for selected customers. I have explored options to deny to everyone except the public IP addresses but that is alwasys hard to get from customers and would need continuous maintenance. Therefore the VPN option. I would say at the most 5 customers connect from time to time.
0
 
LVL 4

Expert Comment

by:kruptos
ID: 17158761
You could set up a VPN that will only allow access directly to the server that is acting as FTP. It really depends on what type of firewall you have and it capabilities.

Depending on how secure you want to get will determin the architecture. Personally I woud never run FTP and IIS on SBS if that is your only server. Do you have other servers as well or just the SBS server?

If youc an let me know what type of firewall you have running I may be able to give you some ideas on how to set up the VPN for FTP access.

-Kruptos
0
 

Author Comment

by:birenshukla
ID: 17292213
Thanks. Will try that. I have been continuoing to deny bad guys but that is about it. I am going to get a industry grade firewall.
0

Featured Post

Put Machine Learning to Work--Protect Your Clients

Machine learning means Smarter Cybersecurity™ Solutions.
As technology continues to advance, managing and analyzing massive data sets just can’t be accomplished by humans alone. It requires huge amounts of memory and storage, as well as high-speed processing of the cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Recently, Microsoft released a best-practice guide for securing Active Directory. It's a whopping 300+ pages long. Those of us tasked with securing our company’s databases and systems would, ideally, have time to devote to learning the ins and outs…
Auditing domain password hashes is a commonly overlooked but critical requirement to ensuring secure passwords practices are followed. Methods exist to extract hashes directly for a live domain however this article describes a process to extract u…
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, just open a new email message. In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
This video Micro Tutorial shows how to password-protect PDF files with free software. Many software products can do this, such as Adobe Acrobat (but not Adobe Reader), Nuance PaperPort, and Nuance Power PDF, but they are not free products. This vide…
Suggested Courses

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question