Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Windows Server 2008 Firewall ?

Reply
Fix Vista Errors
Thread Tools Display Modes

Windows Server 2008 Firewall ?

 
 
Paul
Guest
Posts: n/a

 
      11-10-2009



Hi All,

I am having difficulty understanding the firewall in Windows Server 2008 and
wondering if anyone can enlighten me.

Honestly speaking, I think this new firewall presents its own set of
security issues as it is more likely that a misconfiguration will open the
firewall over securing it. Having worked with ISA, Astaro, BIND DNS, and
many other different apparatus and understand the concept of a perimeter
wall, and the freedom to define the perimeter, but W2008FW has this
predefined in PRIVATE/PUBLIC/DOMAIN.

So my first question is what are the above definitions (ACLs) and how do I
work with them?

How do they relate to multihomed DCs? For example, I would expect to define
the external adapter as PUBLIC, and proceed with a harderning of the wall on
the external addresses, and Private the local net (e.g. 192.168.1.0/24),
which I would like to open up to access our applications.

However whatever I do seems to produce weird and strange results.

To let you know what I am trying to do:

1. Open POP3 in on the external adapter only.
2. Open HTTP/HTTPS in on the external adapter only.

I tried to simply allow 110 across all profiles on external adapter only but
email clients have problem logging in. Same as HTTP. When I do an IP scan it
says the ports are open. Confusing.


 
Reply With Quote
 
Meinolf Weber [MVP-DS]
Guest
Posts: n/a

 
      11-10-2009
Hello Paul,

The definitions are made for home(PRIVATE), overall internet, internet cafe
for example(PUBLIC) and DOMAIN as it's describe itself. So you have 3 different
profiles you can configure for your users needs.

You should NOT multihome any DC. The only exception is SBS, this is especially
built for different configuration options then the normal server versions.
See here about multihoming:
http://msmvps.com/blogs/acefekay/arc...-adapters.aspx

Additional start here for the Windows Firewall:
http://technet.microsoft.com/en-us/n.../bb545423.aspx

http://www.windowsnetworking.com/art...C-snap-in.html

Also the Windows Firewall Newsgroup should be the better place for your questions:
http://www.microsoft.com/communities...&lang=en&cr=US



Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> Hi All,
>
> I am having difficulty understanding the firewall in Windows Server
> 2008 and wondering if anyone can enlighten me.
>
> Honestly speaking, I think this new firewall presents its own set of
> security issues as it is more likely that a misconfiguration will open
> the firewall over securing it. Having worked with ISA, Astaro, BIND
> DNS, and many other different apparatus and understand the concept of
> a perimeter wall, and the freedom to define the perimeter, but W2008FW
> has this predefined in PRIVATE/PUBLIC/DOMAIN.
>
> So my first question is what are the above definitions (ACLs) and how
> do I work with them?
>
> How do they relate to multihomed DCs? For example, I would expect to
> define the external adapter as PUBLIC, and proceed with a harderning
> of the wall on the external addresses, and Private the local net (e.g.
> 192.168.1.0/24), which I would like to open up to access our
> applications.
>
> However whatever I do seems to produce weird and strange results.
>
> To let you know what I am trying to do:
>
> 1. Open POP3 in on the external adapter only.
> 2. Open HTTP/HTTPS in on the external adapter only.
> I tried to simply allow 110 across all profiles on external adapter
> only but email clients have problem logging in. Same as HTTP. When I
> do an IP scan it says the ports are open. Confusing.
>



 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Re: Windows 2000 to 2008 AD upgrade. Meinolf Weber [MVP-DS] Server Migration 0 11-10-2009 06:53 AM
OT: all systems on network slow for last week or so Gregg Hill Windows Small Business Server 15 10-30-2009 01:43 AM
Windows Server 2003 does not open its own share Rick Clapp Windows Server 1 10-29-2009 05:18 PM
Re: Can I migrate/upgrade Windows Server 2008 32-bit to 64-bit? Meinolf Weber [MVP-DS] Server Migration 0 10-26-2009 11:37 AM
Corrupt Files juerg Windows Vista Installation 10 07-12-2007 05:38 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59