Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

How to close those ports

Posted on 2008-06-09
9
Medium Priority
?
385 Views
Last Modified: 2008-07-08
I have installed SBS 2003 Standard (No Isa Server) and ran the wizard that installs the Firewall. Now I check with grc.com ( Shields up) and I have apparently several ports open (21, 25, 80. 443). How can that be? And how can I close them?

Many thanks
0
Comment
Question by:TheoRichel
  • 3
  • 2
  • 2
  • +1
9 Comments
 
LVL 7

Expert Comment

by:CorruptedLogic
ID: 21745608
Port 21 is FTP, 25 is SMTP (for email), 80 is HTTP and 443 is HTTPS, you need to have these ports open in order to send/receive mail, browse the web etc.
0
 

Author Comment

by:TheoRichel
ID: 21745879
Thanks. So nothing to worry about? In the past when I worked with ISA-server grc-reported that I operated entirely in stealth modus.
0
 
LVL 7

Expert Comment

by:CorruptedLogic
ID: 21745895
What else is running on the server? I'd guess Exchange and IIS?
0
The Lifecycle Approach to Managing Security Policy

Managing application connectivity and security policies can be achieved more effectively when following a framework that automates repeatable processes and ensures that the right activities are performed in the right order.

 

Author Comment

by:TheoRichel
ID: 21745950
Yes, the standard package.
0
 
LVL 7

Assisted Solution

by:CorruptedLogic
CorruptedLogic earned 600 total points
ID: 21745974
I would say not to worry, just be sure that you have all the standard stuff enabled/disabled on Exchange (relaying etc, which i think is disabled out of the box these days). I'm not overly familiar with the built in SBS firewall ( I always have an appliance firewall like a PIX on my networks), but from the sounds of things, you'll be fine. You could always block port 21 (ftp) as a test and see if the shieldsup test reports anything different.
0
 
LVL 38

Expert Comment

by:Hypercat (Deb)
ID: 21746001
You should close port 21 (FTP) incoming unless you need to allow incoming FTP traffic.  FTP is very insecure and vulnerable to hacking. Unless you don't have a hardware firewall in place, that would be preferable and more secure than using the Internet connection sharing capabilities of your SBS server.  However, if you don't have a hardware firewall, then you can close the ports you need to close by editing the firewall configuration.
0
 
LVL 38

Accepted Solution

by:
Hypercat (Deb) earned 700 total points
ID: 21746038
Sorry - my bad.  I think you need to edit the TCP/IP settings on the server NIC itself:

http://support.microsoft.com/kb/816792/en-us
0
 
LVL 78

Assisted Solution

by:Rob Williams
Rob Williams earned 700 total points
ID: 21746788
If you want to close any of those ports run the CEICW (Configure E-mail and Internet Conection Wizard) located under server management | Internet and e-mail | connect to the Internet. Within the wizard there is one window with a series of check boxes for the above services. Only check those you plan to use. Best practices states that FTP and Http should not be allowed on a domain controller (SBS). The common/safe ones used on SBS are
443 for OWA
443 & 4125 RWW
444 Sharepoint
A;ll of these use SSL so are quite secure.
0
 
LVL 78

Expert Comment

by:Rob Williams
ID: 21954405
Thanks TheoRichel.
Cheers !
--Rob
0

Featured Post

The Lifecycle Approach to Managing Security Policy

Managing application connectivity and security policies can be achieved more effectively when following a framework that automates repeatable processes and ensures that the right activities are performed in the right order.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The problem of the system drive in SBS 2003 getting full continues to be an issue, even though SBS 2008 and SBS 2011 are both in the market place.  There are several solutions to this, including adding additional drive space or using third party uti…
The DROP (Spamhaus Don't Route Or Peer List) is a small list of IP address ranges that have been stolen or hijacked from their rightful owners. The DROP list is not a DNS based list.  It is designed to be downloaded as a file, with primary intention…
When cloud platforms entered the scene, users and companies jumped on board to take advantage of the many benefits, like the ability to work and connect with company information from various locations. What many didn't foresee was the increased risk…
The Relationships Diagram is a good way to get an overall view of what a database is keeping track of. It is also where relationships are defined. A relationship specifies how two tables connect to each other. As you build tables in Microsoft Ac…

572 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question