Click here to get back home

Windows 2003 firewall

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Windows 2003 firewall mrss 11-22-2005
Posted by mrss on November 22, 2005, 12:09 pm
Please log in for more thread options
I have recently installed SP1 on our Win 2003 server, and activated the
firewall. The applications and services running on this server, like DHCP
and Mcafee EPO virus protection seem to be working, after some negotiation
with the firewall. Yesterday I enabled logging of dropped connections in
Event Viewer, and I now see a large number of logon failures, mostly for
local services, like lsass.exe and sqlmangr.exe, which event viewer says the
firewall has "detected listening on port ...." Do I need to manually open
these ports? The most frequent blocked connection is cqsmgr.exe, which I
understand is a Compaq ditty, doing I don't know what. My server is a
Proliant. If I don't see any ill effect, should I just leave these, or is
the dropping of these connections provoking a storm of requests to my server
that will slow it down?

Posted by Steven L Umbach on November 22, 2005, 5:44 pm
Please log in for more thread options
Make sure that you look at the firewall logs also to see what traffic is
being dropped. If you are seeing a large number of logon failures that may
be a reason for concern to maintain functionality if they are legitimate
connections. The logon events should show the source computer that is
causing these events and you would want to investigate further to see if the
source computer is working correctly or not and look in it's logs for
failure events that may help you determine what is going on. Such logon
failures would indicate more is being blocked than typical broadcast
oise. --- Steve


>I have recently installed SP1 on our Win 2003 server, and activated the
> firewall. The applications and services running on this server, like DHCP
> and Mcafee EPO virus protection seem to be working, after some negotiation
> with the firewall. Yesterday I enabled logging of dropped connections in
> Event Viewer, and I now see a large number of logon failures, mostly for
> local services, like lsass.exe and sqlmangr.exe, which event viewer says
> the
> firewall has "detected listening on port ...." Do I need to manually open
> these ports? The most frequent blocked connection is cqsmgr.exe, which I
> understand is a Compaq ditty, doing I don't know what. My server is a
> Proliant. If I don't see any ill effect, should I just leave these, or is
> the dropping of these connections provoking a storm of requests to my
> server
> that will slow it down?



Similar ThreadsPosted
Firewall of Windows 2003 October 2, 2005, 1:31 am
Is Windows 2003 firewall safe? March 23, 2006, 8:28 am
Antivirus+Firewall for Windows Server 2003 May 25, 2006, 9:59 am
Saving a Windows 2003 Firewall Configuration? December 15, 2006, 11:28 pm
Simple question regarding Windows 2003 Firewall April 1, 2007, 11:35 pm
Windows 2003 built-in firewall prevents AD from synching across DCs December 8, 2005, 11:24 am
properly configured windows 2003 server OK without a hardwre firewall? November 24, 2007, 12:00 pm
SBS 2003 - XP SP2 - Firewall GPO issues December 7, 2005, 1:25 pm
Win 2003 Firewall Problem. Ahhh January 4, 2008, 2:55 pm
ftp + windows firewall September 20, 2006, 6:02 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap