Networking Forums

Networking Forums > Computer Networking > Windows Networking > Protect multihomed single 2008 AD server with Windows Firewall Adv

Reply
Thread Tools Display Modes

Protect multihomed single 2008 AD server with Windows Firewall Adv

 
 
Kevin
Guest
Posts: n/a

 
      09-10-2008, 10:26 PM
I have inherited a rather gross setup that I have to make work in as secure a
manner as possible. Ideally, I’d be securing with ISA 2006 but let’s proceed
knowing it’s ugly and we can’t do much about it right now:

-Single server Windows 2008 AD DC (64 bit)
-Exchange 2008 w SP1

-basic SOHO firewall providing DSL internet access to a private subnet we’ll
call WAN.
-RRAS NAT on the server NATting on the WAN network interface on the server.
Internal clients are connected to a second network interface LAN, also a
private (but different from WAN) subnet.

I’m making some assumptive conclusions here so please correct if any of them
are flat wrong…
I have NAT Services and Ports defined but they don't seem to be restricting
traffic. They only allow HTTPS and RDP from WAN to LAN. I think this is due
to Windows Firewall superseding those NAT rules.
When I look at the WF-AdvSec interface, I see the various location profiles.
As this is a server, I can’t see it changing so it will likely always be in
Domain Profile. I further see all the default Allows that permit all the
nominal server traffic but on Any interface. This likely includes the WAN
interface, which I really don’t want.
Am I correct thus far? If so, then is there an efficient way I can restrict
these rules to only operate on the LAN interface and provide for different
rules on the LAN interface? What is required to do this?

Thanks.

Kevin

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Switch firewall profile public <-> private in Server 2008/Vista Jeff Stark Windows Networking 0 02-27-2009 09:32 PM
Server 2008 with Hyper-V - domain controller - Firewall GUI's show firewall ON, but netsh reports firewall OFF Bruce Sanderson Windows Networking 7 10-07-2008 09:57 AM
Firewall blocks File sharing in Windows 2008 connected to the domain. MarcusB Windows Networking 4 04-12-2008 02:28 PM
Multihomed Windows Server 2003 for Backups ChrisW Windows Networking 3 02-10-2006 10:46 PM
Solution to a multihomed Windows 2003 VPN server Leandro Becker Windows Networking 6 06-08-2004 04:26 PM



1 2 3 4 5 6 7 8 9 10 11