DanDanFireMan
Aug 15 2003, 11:43 AM
How To: Enable TCP/IP Filtering on Windows 2003 Server for use with Ensim Webhosting
WARNING!!!! Use at your own risk! Failure to successfully complete this howto or not following it correctly could require manual intervention to enable you to reconnect to the box. I tested this on 2 servers without issue.
Connect to the Windows 2003 Server with Remote Desktop
Login to the Server.
Go to Start -> Control Panel -> Network Connections -> Local Area Connection
Click Properties
Click Internet Protocol (TCP/IP)
Click Properties
Click Advanced
Click the Options Tab
Highlight TCP/IP filtering and then Click Properties
Check the box labeled "Enable TCP/IP Filtering (All adapters)"
At this point, you should select the TCP/UDP/IP Ports and Protocols necessary to operate the server. You will select "Permit Only" and list the ports or protocols you will permit to pass through the filter.
Here are the ones I selected and what they are used for.
TCP Ports
20 - FTP
21 - FTP
25 - SMTP
53 - DNS
80 - HTTP
110 - POP3
443 - HTTPS
3389 - RDP - Remote Desktop Connection !!!!IF YOU DON'T DO THIS, YOU WILL NOT BE ABLE TO GET BACK INTO THE SERVER!!!!
8080 - Urchin Webserver
19638 - Ensim
UDP Ports
53 - DNS
IP Protocols
1 - ICMP (Optional - Used for ping and other administrative packets)
6 - TCP
17 - UDP
Select OK, OK, OK, OK, then Yes to REBOOT
Hopefully if you have performed this correctly, you should be able to reconnect to your server after approximately 5 minute reboot.
DanDanFireMan
Aug 15 2003, 11:45 AM
FYI as a followup to the above. Ensim creates anonymous ftp connections for each domain and uses a nonstandard port number for each site starting at around 10003. If you will be supporting anonymous ftp on name based sites with these numbers, you will need to enable the tcp ports used by each site that will use anonymous ftp on name based sites.
BlueChris
Aug 15 2003, 01:08 PM
Thx for the How-To m8.. but there are big troubles with Multiple ips with this way.. pls read here
http://forum.rackshack.net/showthread.php?...&threadid=29424
kelani
Aug 18 2003, 11:04 AM
Also, don't forget to add in TCP port 8098 if you want to get to the default-installed Web management.
jchin
Sep 10 2003, 09:59 PM
How does tcp/ip filtering affect the speed of your servers? It seems to slow down noticebly for me.
hostu
Nov 29 2003, 07:52 PM
dandan, would this be the same for a 2003 standard server ?
thanks
chuck
kelani
Dec 5 2003, 11:03 AM
Same here. I noticed a significant and annoying slowdown when enabling filtering. It's almost too much a price to pay.
rubensans
Jan 3 2004, 12:42 PM
What are the diferences between:
1) TCP/IP Filtering
2) ICF, Internet Connection Firewall
I have try the first and after activating TCP/UDP 53, the DNS server was working but cannot receive the responses about DNS queries.
Best Regards,
Ruben.
rubensans
Jan 13 2004, 07:21 AM
anyone?
LighthousePoint
Jan 13 2004, 10:48 AM
TCP/IP filtering is just that : a filter for TCP/IP. the Internet Connection Firewall is a sad excuse for blocking a few ports.
I highly recommend a good stateul packet-inspection firewall, such as visnetic.
gummyAvenger
Jan 28 2004, 09:22 PM
This is probably a really dumb question, but...
I've got TCP/IP filtering enabled, and I've got all the ports listed above "allowed", but now I am no longer able to browse/ping websites while logged in via RDP. All sites and everything else work great though. Am I missing a port or something?
gummyAvenger
Jan 29 2004, 11:10 AM
Not such a dumb question I guess... nobody knows?
Well, I've narrowed it down to UDP. If I do "Permit All" for UDP I can browse the internet from the server. The only port I've got enabled for UDP is 53. Are there any others I need?
gummyAvenger
Jan 30 2004, 10:07 AM
I found out that (I think) the DNS request gets sent out on port 53 and comes back on ports >1023. So that was the issue.
Another port you might want to add to that list is 143 for IMAP.
Also, for anyone using Helm:
Make sure to open port 445 or the file manager in the control panel won't work. You'll also get errors when you do a "System Diagnosis" if it's not open.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please
click here.