Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Windows Small Business Server > Re: How do you block port 25 on workstations via SBS 2008/Group Policy?

Reply
Thread Tools Display Modes

Re: How do you block port 25 on workstations via SBS 2008/Group Policy?

 
 
James Hurrell
Guest
Posts: n/a

 
      08-06-2010
On 06/08/2010 11:29, eggedd2k wrote:
> I have recently read that a best practice on the network was to block
> port 25 on all workstations that connect to the exchange box. The
> exchange server should be the only computer allowing smtp port 25
> traffic, therefore reducing the chance of a mass-mailing worm to do
> its magic on a workstation, invoke its own smtp service, and send out
> spam. Workstations would still be allowed to send out mail via
> Exchange and Outlook, but no port 25 traffic on the individual
> machines
>
> My domain controller is SBS 2008 with Exchange 2007. The client
> workstations are mostly XP with a couple of Windows 7 systems.
>
> There's the Security section within the SBS Console however I can't
> figure out how to put a block on all workstations from sending port 25
> outbound traffic.
>
> Can anyone help?


Why don't you do this at your edge firewall device? Block the network's
entire IP address range for outbound from any port to port 25 outbound
and then specifically allow only the SBS IP address to make outgoing
SMTP connections...
 
Reply With Quote
 
 
 
 
Steve Foster
Guest
Posts: n/a

 
      08-06-2010
eggedd2k wrote:

> I already thought of that however:-
>
> My setup is as follows:
>
>
> Workstations
> ------------------------------------------Switch ------- Webserver
> (win2k rras nat) ------- ISP provided Router/Firewall
> Servers (dc/exchange)
>
>
> As far as I'm aware rras (nat) on win2k doesn't allow blocking of
> individual addresses. Of course the traffic seen by the isp router/
> firewall is that of the webserver only.


RRAS in 2003 certainly lets you do selective access, I'd expect RRAS in
2000 to be similar.

Of course, the bigger question is WTF are you using a Win2000 server as
a NAT device?

I'd be inclined to blow it away, and install Untangle on that hardware
instead, if you want a decent firewall between you and the internet
(and don't want to spend much $$$).

--
Steve Foster
For SSL Certificates, Domains, etc, visit.:
https://netshop.virtual-isp.net
 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
No network drive mapping after joining Active Directory ? Patrick Active Directory 29 05-05-2010 12:21 PM
Access Denied error while edit some of the GPOs in Windows 2003 AD Laljeev M Active Directory 24 03-25-2010 01:40 PM
Overriding default SBS 2008 policies Andrew M. Saucci, Jr. Windows Small Business Server 4 02-08-2010 07:36 AM
Re: VPN keeps dropping at the 3 minute mark Cliff Galiher Windows Small Business Server 3 12-07-2009 02:36 PM
cannot install Vista ACPI error Salsakidd Windows Vista Installation 6 10-10-2007 10:12 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59