Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Update > Windows Updates: Firewall setting for outbound traffic

Reply
Thread Tools Display Modes

Windows Updates: Firewall setting for outbound traffic

 
 
bstover@norcalmutual.com
Guest
Posts: n/a

 
      02-16-2005
I've been hammering on this problem for a long time, and there does not
to be a real solution for me. Hopefully someone from this group, maybe
an employee from Microsoft can help out.

I have a network of 50 servers and 400 users. The servers run Win2k
and Win2k3 and sit behind a firewall. For obvious reasons, I limit
outbound traffic from the servers to the internet. This includes HTTP.
I don't want my servers to be accessible, and I don't want them
accessing any unnecessary external resources.

For example, We've had a flood of trojans in the past few weeks. The
trojans call a server (outbound traffic) via HTTP then download the
virus back in to the network. If I allow all outbound HTTP, then this
opens my servers to being vulnerable.

My problem: I need to update my servers with MS Critical Patches.
This means that I must create outbound rules on my firewall allowing
HTTP access to specific URLS or SUBNETS. I've allowed the following
based on the articles I've read in the groups and on MS, but there are
other sites involved as well that are not documented, and the IP
addresses are constantly changing.

activex.microsoft.com
download.windowsupdates.com
crl.microsoft.com
v3stats.windowsupdates.microsoft.com
v4.windowsupdates.microsoft.com
v5.windowsupdates.microsoft.com

207.46.0.0/16
64.4.0.0/16
38.113.0.0/16
64.62.0.0/16
64.152.0.0/16

Does anypne out there have a comprehensive listing of URLS and SUBNETS
that need to be included as destination addresses in an outbound HTTP
firewall policy to make sure that Windows Updates will work
consistently?

Thanks!


Your help is appreciated.

 
Reply With Quote
 
 
 
 
Pat Walters [MSFT]
Guest
Posts: n/a

 
      02-23-2005
,

I am more than happy to help. There are really three solution steps here,
following the principle of least privilege:

A. The trusted zone for Windows Update should be a separate one in your
firewall and:
1. Only have one trusted sites zone, and include only the following 3
websites:

http://*.windowsupdate.microsoft.com
https://*.windowsupdate.microsoft.com
http://download.windowsupdate.com

2. Remove all specific IP addresses and any ranges, as these change
without notice.

B. Because of the Exception list in so many of these firewalls, there should
be an exception object or zone, and it should perfectly mirror the trusted
zone spelled out in "A".

C. Make sure your firewall allows, at least to the zones above, Win32
Generic Service and ActiveX controls. This will be required soon for
Windows 2000 and Windows Server 2003 machines, which right now are using the
v4.windowsupdate.microsoft.com website.

This should work consistently for you, barring any other restrictions.
Please reply back to this newsgroup and let me know whether or not you were
successful.

Sincerely,

Pat Walters [MSFT]


<> wrote in message
news: ups.com...
> I've been hammering on this problem for a long time, and there does not
> to be a real solution for me. Hopefully someone from this group, maybe
> an employee from Microsoft can help out.
>
> I have a network of 50 servers and 400 users. The servers run Win2k
> and Win2k3 and sit behind a firewall. For obvious reasons, I limit
> outbound traffic from the servers to the internet. This includes HTTP.
> I don't want my servers to be accessible, and I don't want them
> accessing any unnecessary external resources.
>
> For example, We've had a flood of trojans in the past few weeks. The
> trojans call a server (outbound traffic) via HTTP then download the
> virus back in to the network. If I allow all outbound HTTP, then this
> opens my servers to being vulnerable.
>
> My problem: I need to update my servers with MS Critical Patches.
> This means that I must create outbound rules on my firewall allowing
> HTTP access to specific URLS or SUBNETS. I've allowed the following
> based on the articles I've read in the groups and on MS, but there are
> other sites involved as well that are not documented, and the IP
> addresses are constantly changing.
>
> activex.microsoft.com
> download.windowsupdates.com
> crl.microsoft.com
> v3stats.windowsupdates.microsoft.com
> v4.windowsupdates.microsoft.com
> v5.windowsupdates.microsoft.com
>
> 207.46.0.0/16
> 64.4.0.0/16
> 38.113.0.0/16
> 64.62.0.0/16
> 64.152.0.0/16
>
> Does anypne out there have a comprehensive listing of URLS and SUBNETS
> that need to be included as destination addresses in an outbound HTTP
> firewall policy to make sure that Windows Updates will work
> consistently?
>
> Thanks!
>
>
> Your help is appreciated.
>



 
Reply With Quote
 
bstover@norcalmutual.com
Guest
Posts: n/a

 
      03-02-2005
Hi, thanks for your help, Pat.

My problem is that I cannot do wildcards for DNS entries on my
firewall. I use a Netscreen 208. I can enter DNS names instead of IP
addresses, and then my firewall does a DNS refresh every 4 hours
(lowest possible interval) then it caches the address. Because of the
4 hour interval, the IP address that the firewall sees is different
than the IP address the server is trying to reach to get its updates.
When I try to enter a wildcard for DNS, it cannot resolve to a specific
IP address.

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Firewall message - Wudfhost.exe attempting outbound traffic - to IP 67.135.105.130... DA1745 Windows Vista Performance 3 05-16-2009 10:26 PM
Windows Firewalls - blocking outbound traffic - best set-up? Steve Campbell Windows Vista Performance 4 11-06-2007 09:52 PM
Help, Vista's firewall started to work with outbound traffic, and I don't know how to stop it!!!!! Juan I. Cahis Windows Vista General Discussion 10 07-16-2007 04:18 AM
Firewall blocks outbound traffic even if outbound rule exists Curt Windows Vista Security 21 03-22-2007 05:08 PM
Vista firewall not blocking outbound traffic despite explicit rules to do so Roof Fiddler Windows Vista Security 11 02-12-2007 07:08 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59