Click here to get back home

Seeking Advice- Securing Server Traffic

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Seeking Advice- Securing Server Traffic hedon 01-06-2007
Posted by hedon on January 6, 2007, 7:21 pm
Please log in for more thread options
We have a member Server. W2K3, with dual NICs that responds to domain
traffic Vlan, 192.160.1.0/27 and Internet Vlan, 192.168.1.32/27. Internet
traffic is outbound only for purposes of updating WSUS, AV pattern updates.
The server is protected by Cisco CBAC Firewall.

How can I force all update traffic (http) to use the 192.168.1.32 vlan? Is
their a better way I can design network flow, with the priority on server
protection.

Thanks in advance for help


Posted by Roger Abell [MVP] on January 6, 2007, 8:24 pm
Please log in for more thread options
I do not know what capabilities your AV product offers.
WSUS is however built upon IIS, and IIS can be configured
as to IP for the site (instead perhaps your current, the default
of All Unassigned). IIS will only use the defined IP for the
responding site, i.e. one in 192.168.1.32/27 subnet.
In addition, another host-based approach is to use IPsec
in a filtering mode to restrict the port availability so that
http/https and whatever the AV uses are allowed only on
the desired IP.

> We have a member Server. W2K3, with dual NICs that responds to domain
> traffic Vlan, 192.160.1.0/27 and Internet Vlan, 192.168.1.32/27. Internet
> traffic is outbound only for purposes of updating WSUS, AV pattern
> updates.
> The server is protected by Cisco CBAC Firewall.
>
> How can I force all update traffic (http) to use the 192.168.1.32 vlan? Is
> their a better way I can design network flow, with the priority on server
> protection.
>
> Thanks in advance for help
>



Similar ThreadsPosted
Securing Remote Desktop To Server August 11, 2005, 10:30 am
Securing Administrator password on a windows 2003 server May 15, 2008, 8:36 pm
Traffic between two networking cards, HELP October 15, 2005, 7:43 pm
Intermittent traffic issue March 19, 2006, 10:44 am
Security Configuration Advice December 20, 2005, 3:00 am
advice on configuring a small network March 2, 2006, 5:38 pm
Need advice: Security GPO for member servers April 19, 2006, 1:36 pm
Group permission AD advice needed. September 8, 2007, 9:11 pm
Allowing SNMP traffic through "Windows Firewall" on WIN2K3 SP1 October 4, 2005, 7:52 am
Need advice: Security policies for member servers April 19, 2006, 2:46 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap