Networking Forums

Networking Forums > Computer Networking > Windows Networking > TCP/IP and ICMP filtering

Reply
Thread Tools Display Modes

TCP/IP and ICMP filtering

 
 
George Valkov
Guest
Posts: n/a

 
      04-04-2004, 04:49 PM
Hello!

I want to use a Windows 2003 Enterprise Server for FTP only.
The server will be available on two networks:
1. NIC 1 (local area network)
2. VPN established via NIC 1 (
Device Name = WAN Miniport (PPTP)
Server Port = TCP 1723
Server Type = PPP
Authentication = MS CHAP V2
Transports = TCP/IP
)

I have stoped on three ways for protection and I want to minimize the system
resources used for filtering the network trafic. I also want to block the
ICMP trafic.
1. TCP/IP filtering on the Advanced TCP/IP Settings for the NIC 1(
TCP Ports: Permit Only (20, 21, 1723)
UDP Ports: Permit Only (none)
IP Protocols: Permit Only (which protocols should I enable here? Where can
I find more information about the mapping between names and numbers of IP
protocols?)
Are there missing ports that I need to enable?
Can I block ICMP from this dialog?
)

2. IP Security Policies (
Block all ICMP trafic
Block all UDP trafic
Dynamic: Default Responce: Kerberos
)

3. Internet Connection Firewall (ICF) Service (
ICMP - any requests are blocked.
Open TCP 20 = FTP Data
Open TCP 21 = FTP Control
)


Which protection method or group of methods are the optimal solution for
performance and security in this scenario?



Thank You for any support!

George Valkov




 
Reply With Quote
 
 
 
 
Jeff Cochran
Guest
Posts: n/a

 
      04-04-2004, 08:47 PM
On Sun, 4 Apr 2004 19:49:59 +0300, "George Valkov"
<(E-Mail Removed)> wrote:

>Hello!
>
>I want to use a Windows 2003 Enterprise Server for FTP only.
>The server will be available on two networks:
>1. NIC 1 (local area network)
>2. VPN established via NIC 1 (
> Device Name = WAN Miniport (PPTP)
> Server Port = TCP 1723
> Server Type = PPP
> Authentication = MS CHAP V2
> Transports = TCP/IP
>)
>
>I have stoped on three ways for protection and I want to minimize the system
>resources used for filtering the network trafic. I also want to block the
>ICMP trafic.
>1. TCP/IP filtering on the Advanced TCP/IP Settings for the NIC 1(
> TCP Ports: Permit Only (20, 21, 1723)
> UDP Ports: Permit Only (none)
> IP Protocols: Permit Only (which protocols should I enable here? Where can
>I find more information about the mapping between names and numbers of IP
>protocols?)
> Are there missing ports that I need to enable?
> Can I block ICMP from this dialog?
>)
>
>2. IP Security Policies (
> Block all ICMP trafic
> Block all UDP trafic
> Dynamic: Default Responce: Kerberos
>)
>
>3. Internet Connection Firewall (ICF) Service (
> ICMP - any requests are blocked.
> Open TCP 20 = FTP Data
> Open TCP 21 = FTP Control
>)
>
>
>Which protection method or group of methods are the optimal solution for
>performance and security in this scenario?


4) Hardware firewall, properly configured and monitored.

Jeff
 
Reply With Quote
 
George Valkov
Guest
Posts: n/a

 
      04-05-2004, 07:39 PM
I understand that in a high end server envinronment I should use a hardware
firewall.
I want to compare the performance between
TCP/IP filtering
IP Security policy
Internet Connection Firewall
and optimize the performance of my home pc.
I also want to know if I need to enable any protocols for the TCP/IP
filtering
so that I can connect to the VPN server.


George Valkov




"Jeff Cochran" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
> On Sun, 4 Apr 2004 19:49:59 +0300, "George Valkov"
> <(E-Mail Removed)> wrote:
>
> >Hello!
> >
> >I want to use a Windows 2003 Enterprise Server for FTP only.
> >The server will be available on two networks:
> >1. NIC 1 (local area network)
> >2. VPN established via NIC 1 (
> > Device Name = WAN Miniport (PPTP)
> > Server Port = TCP 1723
> > Server Type = PPP
> > Authentication = MS CHAP V2
> > Transports = TCP/IP
> >)
> >
> >I have stoped on three ways for protection and I want to minimize the

system
> >resources used for filtering the network trafic. I also want to block the
> >ICMP trafic.
> >1. TCP/IP filtering on the Advanced TCP/IP Settings for the NIC 1(
> > TCP Ports: Permit Only (20, 21, 1723)
> > UDP Ports: Permit Only (none)
> > IP Protocols: Permit Only (which protocols should I enable here? Where

can
> >I find more information about the mapping between names and numbers of IP
> >protocols?)
> > Are there missing ports that I need to enable?
> > Can I block ICMP from this dialog?
> >)
> >
> >2. IP Security Policies (
> > Block all ICMP trafic
> > Block all UDP trafic
> > Dynamic: Default Responce: Kerberos
> >)
> >
> >3. Internet Connection Firewall (ICF) Service (
> > ICMP - any requests are blocked.
> > Open TCP 20 = FTP Data
> > Open TCP 21 = FTP Control
> >)
> >
> >
> >Which protection method or group of methods are the optimal solution for
> >performance and security in this scenario?

>
> 4) Hardware firewall, properly configured and monitored.
>
> Jeff



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Ping and ICMP Rusty Lady Broadband 4 09-27-2010 06:11 PM
ICMP benchmark? Dan Stromberg Linux Networking 3 12-01-2005 05:45 PM
Tunnel ICMP? Davey SM4 Linux Networking 6 02-07-2004 08:10 AM
ICMP settings Dan S. Windows Networking 0 07-07-2003 04:48 PM
ICMP traffic Chip Orange Wireless Internet 2 07-01-2003 06:37 AM



1 2 3 4 5 6 7 8 9 10 11