?
Solved

Server 2008 Firewall Baseline and app pools

Posted on 2013-01-24
3
Medium Priority
?
276 Views
Last Modified: 2013-01-29
have about 200 servers running windows 2003 server and alot of custom applications on network.  Migrating to 2008/2012 and I need to be able to easily transition firewall rule.  What i'm looking for is the procedural method for opening firewall ports based on requirements of the applications in multiple application pools.  And if someone knows a few ways of testing that would be great.  Ultimately We will want to enforce these via GPO based on AD security groups.  

Any help with info would be great.
0
Comment
Question by:leadtheway
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 64

Accepted Solution

by:
btan earned 1500 total points
ID: 38818528
Looks like if GPO is not leverage in older 2003 version, it will be quite challenging to port rule per machine over to 2008 server. Not to say it has 200 machines to make it more challenging. There would need to have a baseline set of rules identified and have it configured in 2008 GPO and push down, making sure it works as it is as base image before starting to customised per machine due to use of different application etc.

Also note that in 2003, Group Policy is via the Windows Firewall section under Administrative Templates > Network > Network Connections. Most setting had to be configured manually in the past but with newer 2008 version,  you configured the firewall via group policy to Windows Settings > Security Settings > Windows Firewall with Advanced Security which has enable features such as importing and exporting firewall rules.

But i see the main thing as of now is to have the list of ports for base and additional one that are unique before we even say about importing rules which is just configuration at central and push down subsequently (domain joined machine I assumed).

check out this article on the identification of ports which i thought may be useful considerations. One thing we may want to consider is that is Netsh comand for Windows FW which can be useful for batch push down in login script etc means (or standalone shared drive, user guided execution ...)

http://msmvps.com/blogs/acefekay/archive/2011/11/01/active-directory-firewall-ports-let-s-try-to-make-this-simple.aspx

http://technet.microsoft.com/en-us/library/cc771046(v=ws.10).aspx
http://technet.microsoft.com/en-us/library/dd734783(v=ws.10).aspx
0
 
LVL 1

Author Comment

by:leadtheway
ID: 38818798
what is the easiest way to interview the applications to determine what ports I would need?
0
 
LVL 64

Expert Comment

by:btan
ID: 38821544
0

Featured Post

Office 365 Training for IT Pros

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Always backup Domain, SYSVOL etc.using processes according to Microsoft Best Practices. This is meant as a disaster recovery process for small environments that did not implement backup processes and did not run a secondary domain controller that ne…
Microsoft Office 365 is a subscriptions based service which includes services like Exchange Online and Skype for business Online. These services integrate with Microsoft's online version of Active Directory called Azure Active Directory.
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…
Suggested Courses

764 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question