Click here to get back home

IPSec - allowing access to specific ports on specifc IP addresses

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
IPSec - allowing access to specific ports on specifc IP addresses simonrl 03-11-2008
Posted by simonrl on March 11, 2008, 4:27 pm
Please log in for more thread options
Hope I've got the right group for this question - fist post.

This is a relatively new area for me having recently rented a Win2K3 box to
host some web sites on. I have installed SQL 2005 onto the server and would
like to limit access on 1433 / 1434 to specific IP addresses only.

The server came with a pre-configured 'IP Security Policy on Local Computer'
under the Local Security Settings snap-in. This has a range of pre-defined
rules that can be Deny/Permit/Request Security/Require Security.

There is a pre-defined MSDE/MS SQL rule that AFAICT can either be permit all
or deny all. If I set it to Permit I can connect using SQL Management Studio
remotely. If I set it to Deny I cannot.

The pre-defined rule contained eight filters, 4 each 1433 and 1434 and 4
each UDP and TCP. I have tried setting the Source Address and Destination
Address to the IP address of the server and the IP I want to allow SQL access
to; however all I can acheive is open access to SQL ports or no access at all.

Using this tool is it possible to disallow SQL access to all except specific
IP addresses? Or is that beyond it's capabilities.

Thanks,
Simon

Similar ThreadsPosted
Blocking Specific IP Addresses July 18, 2006, 12:37 pm
Deny Specific Subnet Access to DC July 17, 2006, 4:06 pm
getting IPSec Certificates for VPN access for non domain members January 5, 2007, 11:03 am
Ports 1514 and 4344 October 19, 2005, 11:54 pm
Closing / stealthing ports on 2003 June 27, 2005, 11:09 pm
network filetering my range of IP addresses July 29, 2005, 11:23 am
Blocking IP Addresses-Tagged server June 15, 2008, 9:21 pm
Ports Open On Windows 2003 Server March 8, 2007, 3:18 pm
Allow update of properties without allowing password changes, etc February 2, 2006, 10:29 am
Allowing applets to create and write to a file June 8, 2005, 7:50 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap