Gilles
Nov 3 2004, 05:16 PM
I've tried to install Kerio as it's free remotely on a box, and as it's impossible to enable port without reboot, i can't access to my box
How can i do that on a server here if i pay for one. I don't want to use windows built in, if possible.
Lunch[box]
Nov 3 2004, 09:01 PM
The only way I'm aware of is to pay SM to do it, which is $75.00/hour if I'm not mistaken.
Have you looked at the RRAS Firewall? It's built into Windows, but it's not the default cheap firewall.
klaude
Nov 4 2004, 02:21 PM
Our security group can configure Kerio for you, but there is an administrative charge for this. At the very leasrt you'll need to open a support ticket to unlock your system. I highly reccomend staying away from personal workstation firewalls on your sedicated server. They're great for a system you have local access to, but they can kill a remote server. It's best to use the RRAS solution or spring for a commercial firewall.
Gilles
Nov 4 2004, 02:23 PM
Hello, i'm testing your rras tutorial on an external box which is on a lan. I have access using radmin on port 4899, on internet ip 213.10.21.212 for example, which is connected to a DMZ computer with ip 192.168.0.3. My internet address at home is 82.212.212.212 for example.
In service / ports i have added Radmin on port 4899, with Private address : 192.168.0.3, incoming port : 65430 (outgoing too ?).
I have added address pool : my own range internet, like 82.0 - 82.200
Am I right ?
Could you tell me if i have to restart service, or restart box, or nothing at all ?
thx
Gilles
Nov 4 2004, 02:25 PM
QUOTE (klaude)
Our security group can configure Kerio for you, but there is an administrative charge for this. At the very leasrt you'll need to open a support ticket to unlock your system. I highly reccomend staying away from personal workstation firewalls on your sedicated server. They're great for a system you have local access to, but they can kill a remote server. It's best to use the RRAS solution or spring for a commercial firewall.
hardware firewall is too expensive, i'm going to use RRAS.
Lunch[box]
Nov 4 2004, 04:50 PM
QUOTE (Gilles)
In service / ports i have added Radmin on port 4899, with Private address : 192.168.0.3, incoming port : 65430 (outgoing too ?).
I have added address pool : my own range internet, like 82.0 - 82.200
Am I right ?
Could you tell me if i have to restart service, or restart box, or nothing at all ?
thx
If your using RADMIN on port 4899 then what is the port 65430 for? It should reflect the port being used, i.e. 4899.
There is no need to restart the service, once you make changes they are ready to go.
Gilles
Nov 4 2004, 05:46 PM
yes, made a mistake, it's port 4899. It works.
Just another question, how can i allow pasv connexion for ftp ?
It works for active, but not passive.
Lunch[box]
Nov 6 2004, 12:07 PM
I haven't messed around with it in a while but I seem to remember that port 20 which is FTP Data will allow Passive FTP to work.
Not 100% sure though.....
Argyle
Nov 7 2004, 05:12 AM
For passive FTP to work you need to have an FTP software where you can specify the passive port range. Then you open up these in your firewall.
Example:
port 21 and port 30000-30100 could be specified
To minimize the ports IIS FTP use for passive FTP see:
How To Configure PassivePortRange In IIS
http://support.microsoft.com/?id=555022
Also Internet Explorer act as an active ftp client by default. To change IE to use passive mode see:
HOW TO: Configure Internet Explorer to Use Both the FTP PORT Mode and PASV Mode in Windows 2000
http://support.microsoft.com/?id=309816
Gilles
Nov 11 2004, 11:47 AM
Well i want to configure port range in RRAS Firewall, is it possible ?
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please
click here.