Networking Forums

Networking Forums > Computer Networking > Windows Networking > Basic Firewall Basics

Reply
Thread Tools Display Modes

Basic Firewall Basics

 
 
jeff.loomis@gmail.com
Guest
Posts: n/a

 
      09-23-2005, 06:41 PM
Hi, I'm trying to set up what should be a very simple configuration.

- Windows Server 2003
- VPN access to the server
- No NAT required (no internal clients)
- Basic Firewall blocking all access except the VPN and Remote Desktop

On the first attempt I used the wizard with default settings for remote
access and basic firewall. Unfortunately, this locked me out because
the default configuration is to deny all access and I do not have
physical access to the machine. My hosting service disabled the
routing and remote access server for me so now I'm trying to do it
manually step-by-step.

I have enabled remote access to use an address range. I am now able to
connect to the VPN and access the server via it's internal address in
this range.

My remaining task is to secure the server with Basic Firewall. I added
the NAT/Basic Firewall and added the external network interface with
the "Basic Firewall Only" button checked. I then used the "Services
and Ports" tab to enable the VPN Gateway and Remote Desktop, directing
them to the server's internal address. I have tried leaving the
address pool empty and also filling it with the addresses of the
external interface (it has 3).

The problem is that the basic firewall does not seem to be blocking any
traffic at all. I can still access the web server through the external
interface. I am sure the wizard must be setting up some additional
thing that I am missing. Can anyone help?

My event log shows one interesting error from ipnathlp:

The Network Address Translator (NAT) was unable to request an operation
of the kernel-mode translation module. This may indicate
misconfiguration, insufficient resources, or an internal error. The
data is the error code. 0000: 1f 00 00 00


Thanks,
Jeff Loomis

 
Reply With Quote
 
 
 
 
Robert L [MS-MVP]
Guest
Posts: n/a

 
      09-24-2005, 12:12 AM
This could be the problem. "added the external network interface with the "Basic Firewall Only" button checked". Or check Public interface connected to the internet or configure inbound filter under Basic firewall only.

Bob Lin, MS-MVP, MCSE & CNE
Networking, Internet, Routing, VPN Troubleshooting on http://www.ChicagoTech.net
How to Setup Windows, Network, VPN & Remote Access on http://www.HowToNetworking.com
<(E-Mail Removed)> wrote in message news:(E-Mail Removed) oups.com...
Hi, I'm trying to set up what should be a very simple configuration.

- Windows Server 2003
- VPN access to the server
- No NAT required (no internal clients)
- Basic Firewall blocking all access except the VPN and Remote Desktop

On the first attempt I used the wizard with default settings for remote
access and basic firewall. Unfortunately, this locked me out because
the default configuration is to deny all access and I do not have
physical access to the machine. My hosting service disabled the
routing and remote access server for me so now I'm trying to do it
manually step-by-step.

I have enabled remote access to use an address range. I am now able to
connect to the VPN and access the server via it's internal address in
this range.

My remaining task is to secure the server with Basic Firewall. I added
the NAT/Basic Firewall and added the external network interface with
the "Basic Firewall Only" button checked. I then used the "Services
and Ports" tab to enable the VPN Gateway and Remote Desktop, directing
them to the server's internal address. I have tried leaving the
address pool empty and also filling it with the addresses of the
external interface (it has 3).

The problem is that the basic firewall does not seem to be blocking any
traffic at all. I can still access the web server through the external
interface. I am sure the wizard must be setting up some additional
thing that I am missing. Can anyone help?

My event log shows one interesting error from ipnathlp:

The Network Address Translator (NAT) was unable to request an operation
of the kernel-mode translation module. This may indicate
misconfiguration, insufficient resources, or an internal error. The
data is the error code. 0000: 1f 00 00 00


Thanks,
Jeff Loomis

 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
RDP thru RRAS basic firewall Jeff Vandervoort Windows Networking 3 01-24-2008 11:36 PM
NAT/BASIC Firewall MJG Windows Networking 1 01-04-2006 09:46 PM
IP Routing>NAT/Basic Firewall News Group Windows Networking 2 01-31-2005 06:44 PM
Basic firewall ... Jacek Jurkowski Windows Networking 3 03-02-2004 02:52 PM
basic firewall/NAT setup James Hastie Linux Networking 1 01-07-2004 03:15 PM



1 2 3 4 5 6 7 8 9 10 11