Solved

How to close those ports

Posted on 2008-06-09
9
376 Views
Last Modified: 2008-07-08
I have installed SBS 2003 Standard (No Isa Server) and ran the wizard that installs the Firewall. Now I check with grc.com ( Shields up) and I have apparently several ports open (21, 25, 80. 443). How can that be? And how can I close them?

Many thanks
0
Comment
Question by:TheoRichel
  • 3
  • 2
  • 2
  • +1
9 Comments
 
LVL 7

Expert Comment

by:CorruptedLogic
ID: 21745608
Port 21 is FTP, 25 is SMTP (for email), 80 is HTTP and 443 is HTTPS, you need to have these ports open in order to send/receive mail, browse the web etc.
0
 

Author Comment

by:TheoRichel
ID: 21745879
Thanks. So nothing to worry about? In the past when I worked with ISA-server grc-reported that I operated entirely in stealth modus.
0
 
LVL 7

Expert Comment

by:CorruptedLogic
ID: 21745895
What else is running on the server? I'd guess Exchange and IIS?
0
 

Author Comment

by:TheoRichel
ID: 21745950
Yes, the standard package.
0
Threat Intelligence Starter Resources

Integrating threat intelligence can be challenging, and not all companies are ready. These resources can help you build awareness and prepare for defense.

 
LVL 7

Assisted Solution

by:CorruptedLogic
CorruptedLogic earned 150 total points
ID: 21745974
I would say not to worry, just be sure that you have all the standard stuff enabled/disabled on Exchange (relaying etc, which i think is disabled out of the box these days). I'm not overly familiar with the built in SBS firewall ( I always have an appliance firewall like a PIX on my networks), but from the sounds of things, you'll be fine. You could always block port 21 (ftp) as a test and see if the shieldsup test reports anything different.
0
 
LVL 38

Expert Comment

by:Hypercat (Deb)
ID: 21746001
You should close port 21 (FTP) incoming unless you need to allow incoming FTP traffic.  FTP is very insecure and vulnerable to hacking. Unless you don't have a hardware firewall in place, that would be preferable and more secure than using the Internet connection sharing capabilities of your SBS server.  However, if you don't have a hardware firewall, then you can close the ports you need to close by editing the firewall configuration.
0
 
LVL 38

Accepted Solution

by:
Hypercat (Deb) earned 175 total points
ID: 21746038
Sorry - my bad.  I think you need to edit the TCP/IP settings on the server NIC itself:

http://support.microsoft.com/kb/816792/en-us
0
 
LVL 77

Assisted Solution

by:Rob Williams
Rob Williams earned 175 total points
ID: 21746788
If you want to close any of those ports run the CEICW (Configure E-mail and Internet Conection Wizard) located under server management | Internet and e-mail | connect to the Internet. Within the wizard there is one window with a series of check boxes for the above services. Only check those you plan to use. Best practices states that FTP and Http should not be allowed on a domain controller (SBS). The common/safe ones used on SBS are
443 for OWA
443 & 4125 RWW
444 Sharepoint
A;ll of these use SSL so are quite secure.
0
 
LVL 77

Expert Comment

by:Rob Williams
ID: 21954405
Thanks TheoRichel.
Cheers !
--Rob
0

Featured Post

Find Ransomware Secrets With All-Source Analysis

Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

Join & Write a Comment

If you are like regular user of computer nowadays, a good bet that your home computer is on right now, all exposed to world of Internet to be exploited by somebody you do not know and you never will. Internet security issues has been getting worse d…
I've often see, or have been asked, the question about the difference between the Exchange 2010 SP1 version, available as part of Small Business Server (SBS) 2011, and the “normal” Exchange 2010 SP1 Standard. The answer to the question is relativ…
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
You have products, that come in variants and want to set different prices for them? Watch this micro tutorial that describes how to configure prices for Magento super attributes. Assigning simple products to configurable: We assigned simple products…

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now