Click here to get back home

Data Access.

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Data Access. Angel 07-29-2007
Posted by Angel on July 29, 2007, 7:18 pm
Please log in for more thread options
In a server with a dual network card, i need connect one ip to a network and
other to diferent network card. This is no problem.
But when share a resource, i need that only one interface can connect to
share resource.

Is possible ?


Posted by apo on September 6, 2007, 8:05 am
Please log in for more thread options
yep, you can do that

use a firewall, appoint a ip that cant communicate with a share port( but im
so sorry i dont know the number of a share application port)

but we've other choice

use NTFS permissions and share folder permissions, you can appoint who can
access the resource and who cant, this way can get a same effect with a
firewall, and they get more flexibility than a firewall

> In a server with a dual network card, i need connect one ip to a network
> and
> other to diferent network card. This is no problem.
> But when share a resource, i need that only one interface can connect to
> share resource.
>
> Is possible ?
>

Posted by Angel on November 18, 2007, 4:53 am
Please log in for more thread options
Thanks for responding.

Sorry, but two posible solutions are not valid forme.
First, the firewall close port of all share resources.
Second: that is posible, but i work in a educational center, where
pupil´s data and teacher´s data are stored in a diferent
server(server_pupìl, server_teacher). When a teacher connect to
server_teacher, computer have a special ip and router pass traffic. While, if
pupil tries connect to server_teacher, router stop traffic.
Router pass traffic when a pupil connect to server_pupil

But now are stored in one server, with two network cards.

Any idea ?



"apo" wrote:

> yep, you can do that
>
> use a firewall, appoint a ip that cant communicate with a share port( but im
> so sorry i dont know the number of a share application port)
>
> but we've other choice
>
> use NTFS permissions and share folder permissions, you can appoint who can
> access the resource and who cant, this way can get a same effect with a
> firewall, and they get more flexibility than a firewall
>
> > In a server with a dual network card, i need connect one ip to a network
> > and
> > other to diferent network card. This is no problem.
> > But when share a resource, i need that only one interface can connect to
> > share resource.
> >
> > Is possible ?
> >

Posted by Steve Riley [MSFT] on November 19, 2007, 11:35 pm
Please log in for more thread options
Firewalls or other network gyrations are not the way to solve this problem.
This is a data security problem, which is best solved using mechanisms
designed for that. In this case, that includes shared folders with proper
NTFS permissions. Define the permissions using access control lists composed
of security groups, which in turn are composed of individual user IDs.

--
Steve Riley
steve.riley@microsoft.com
http://blogs.technet.com/steriley
http://www.protectyourwindowsnetwork.com


> Thanks for responding.
>
> Sorry, but two posible solutions are not valid forme.
> First, the firewall close port of all share resources.
> Second: that is posible, but i work in a educational center, where
> pupil´s data and teacher´s data are stored in a diferent
> server(server_pupìl, server_teacher). When a teacher connect to
> server_teacher, computer have a special ip and router pass traffic. While,
> if
> pupil tries connect to server_teacher, router stop traffic.
> Router pass traffic when a pupil connect to server_pupil
>
> But now are stored in one server, with two network cards.
>
> Any idea ?
>
>
>
> "apo" wrote:
>
>> yep, you can do that
>>
>> use a firewall, appoint a ip that cant communicate with a share port( but
>> im
>> so sorry i dont know the number of a share application port)
>>
>> but we've other choice
>>
>> use NTFS permissions and share folder permissions, you can appoint who
>> can
>> access the resource and who cant, this way can get a same effect with a
>> firewall, and they get more flexibility than a firewall
>>
>> > In a server with a dual network card, i need connect one ip to a
>> > network
>> > and
>> > other to diferent network card. This is no problem.
>> > But when share a resource, i need that only one interface can connect
>> > to
>> > share resource.
>> >
>> > Is possible ?
>> >

Similar ThreadsPosted
Deleting Data permanently November 1, 2005, 10:17 am
BitLocker Data Volume Encryption March 30, 2007, 2:36 pm
Help: How to extract registry data from dead server HDD... October 5, 2005, 2:00 pm
Why Are List Folder / Read Data Combined? November 21, 2005, 10:45 pm
Can I disable Data Encryption Protection in W2K3 Svr? March 24, 2006, 11:42 am
VA Data Breach is a Symptom of a Bigger Problem May 24, 2006, 7:21 pm
VA Data Breach is a Symptom of a Bigger Problem May 24, 2006, 7:21 pm
VA Data Breach is a Symptom of a Bigger Problem May 24, 2006, 7:21 pm
VA Data Breach is a Symptom of a Bigger Problem May 24, 2006, 7:21 pm
VA Data Breach is a Symptom of a Bigger Problem May 24, 2006, 7:21 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap