Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Amazon EC2 - Security Group Settings

Posted on 2014-04-12
8
Medium Priority
?
326 Views
Last Modified: 2014-04-12
I've already modified security settings on my EC2 instance and have gotten what I wanted from doing that (ability to ping and ability to reach the instance via my browser) but I've probably opened the security settings to broadly and compromised security of the instance. I've attached screen shots of the settings, can you help with this?
EC2-Security-Settings.docx
0
Comment
Question by:cbridgman
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 4
8 Comments
 
LVL 25

Expert Comment

by:Zephyr ICT
ID: 39996518
For starters I'd definitely remove the All TCP ports inbound rule ... That's very unsafe!
0
 

Author Comment

by:cbridgman
ID: 39996526
The reason that I put the TCP ports thing in there is that I have installed websphere on the server and deployed a web-based application on it. Now that it is there, I need to be able to access that application's user interface through a browser from any PC I'm on. Before adding the ALL TCP entry, I was unable to do that. Once I added it, I was able to access the application via a browser.

Is there another or better way to do that?
0
 
LVL 25

Expert Comment

by:Zephyr ICT
ID: 39996529
Yeah ... There should be, find out which ports websphere is using and the other applications, maybe you can use netstat to find out which ports are open when you're using the application?

in a command window type "netstat -an" for example ...

For the record, these are all the ports websphere is using apparently: http://publib.boulder.ibm.com/infocenter/wsdoc400/v6r0/index.jsp?topic=/com.ibm.websphere.iseries.doc/info/ae/ae/adrportbase.htm

I'd start with configuring these instead of the all TCP ports.
0
Moving data to the cloud? Find out if you’re ready

Before moving to the cloud, it is important to carefully define your db needs, plan for the migration & understand prod. environment. This wp explains how to define what you need from a cloud provider, plan for the migration & what putting a cloud solution into practice entails.

 

Author Comment

by:cbridgman
ID: 39996530
Okay, I will give that a try. I really am a novice at this kind of stuff so your assistance is really appreciated. I will let you know how that goes.
0
 
LVL 25

Accepted Solution

by:
Zephyr ICT earned 2000 total points
ID: 39996534
No problem, I'm still here for a little while ... We all have to learn, I'm still learning every day ;)
0
 

Author Comment

by:cbridgman
ID: 39996700
RDP solution works like a charm.

Thanks for the expert help.
0
 

Author Comment

by:cbridgman
ID: 39996701
I closed down the ports that are available to TCP and all is working fine.

Again, thanks for the expert help.
0
 
LVL 25

Expert Comment

by:Zephyr ICT
ID: 39996721
Ok, glad to hear it!! Thanks!
0

Featured Post

Python: Series & Data Frames With Pandas

Learn the basics of Python’s pandas library of series & data frames and how we can use these tools for data manipulation.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Is your company's data protection keeping pace with virtualization? Here are 7 dynamic ways to adapt to rapid breakthroughs in technology.
You deserve ‘straight talk’ from your cloud provider about your risk, your costs, security, uptime and the processes that are in place to protect your mission-critical applications.
Internet Business Fax to Email Made Easy - With  eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…
Internet Business Fax to Email Made Easy - With eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…

670 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question