Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

IIS security question

Old Jun 21, 2002 | 12:24 PM
  #1  
Rob Walker's Avatar
Rob Walker
Thread Starter
Scooby Regular
 
Joined: Nov 1999
Posts: 474
Likes: 0
From: Stockport
Post

Hi,

I'm in the process of setting up an IIS server for work. Do I need to run a firewall and virus checker on the server or should it be ok without as long as all the latest patches/fixes are installed?

Cheers
Rob
Reply
Old Jun 21, 2002 | 12:28 PM
  #2  
ADP's Avatar
ADP
Scooby Regular
 
Joined: Apr 2001
Posts: 3,823
Likes: 1
Post

Well is it sat behind any other firewalls???
Reply
Old Jun 21, 2002 | 12:40 PM
  #3  
David_Wallis's Avatar
David_Wallis
Scooby Regular
 
Joined: Nov 2001
Posts: 15,239
Likes: 1
From: Leeds - It was 562.4bhp@28psi on Optimax, How much closer to 600 with race fuel and a bigger turbo?
Post

needs a virus scanner regardless... dont care what you say...

David
Reply
Old Jun 21, 2002 | 01:10 PM
  #4  
Rob Walker's Avatar
Rob Walker
Thread Starter
Scooby Regular
 
Joined: Nov 1999
Posts: 474
Likes: 0
From: Stockport
Post

No its not behind any other firewall, its just a bare server connected to the net.

Cheers
Rob
Reply
Old Jun 21, 2002 | 01:28 PM
  #5  
David_Wallis's Avatar
David_Wallis
Scooby Regular
 
Joined: Nov 2001
Posts: 15,239
Likes: 1
From: Leeds - It was 562.4bhp@28psi on Optimax, How much closer to 600 with race fuel and a bigger turbo?
Post

Connected to the net as in Internet or internal Lan?

If its just sat on internet I would at a minimum block all ports other than 80 and open up whatever you need...

David
Reply
Old Jun 21, 2002 | 01:35 PM
  #6  
Rob Walker's Avatar
Rob Walker
Thread Starter
Scooby Regular
 
Joined: Nov 1999
Posts: 474
Likes: 0
From: Stockport
Post

Sorry.. its connected to the internet.

Can you block ports from within IIS or would I have to run a firewall to do that?

Cheers
Rob
Reply
Old Jun 21, 2002 | 01:45 PM
  #7  
David_Wallis's Avatar
David_Wallis
Scooby Regular
 
Joined: Nov 2001
Posts: 15,239
Likes: 1
From: Leeds - It was 562.4bhp@28psi on Optimax, How much closer to 600 with race fuel and a bigger turbo?
Post

do it under network properties, tcp/ip, properties, advanced, enable security.... I would still recommend a firewall though!

David
Reply
Old Jun 21, 2002 | 01:58 PM
  #8  
Rob Walker's Avatar
Rob Walker
Thread Starter
Scooby Regular
 
Joined: Nov 1999
Posts: 474
Likes: 0
From: Stockport
Post

Nice one. Thanks for your help. I'll go and have a look at firewalls now.

Cheers
Rob
Reply
Old Jun 21, 2002 | 03:08 PM
  #9  
ChrisB's Avatar
ChrisB
Moderator
 
Joined: Dec 1998
Posts: 23,573
Likes: 0
From: Staffs
Post

You need to strip out some of the installed samples etc.

There's a basic lock down guide on for IIS 5 on microsoft.com/technet
Reply
Old Jun 21, 2002 | 03:17 PM
  #10  
stevem2k's Avatar
stevem2k
Scooby Regular
 
Joined: Sep 2001
Posts: 4,670
Likes: 0
From: Kingston ( Surrey, not Jamaica )
Post


Sorry, but the safest thing would be to not install IIS unless you absolutely have to. Can't you use apache ?

And block all ports apart from 80 , and rename the administrator account and run an anti-virus and sit it behind a firewall and all of the other lockdown stuff .

Steve
Reply
Old Jun 21, 2002 | 03:53 PM
  #11  
Rob Walker's Avatar
Rob Walker
Thread Starter
Scooby Regular
 
Joined: Nov 1999
Posts: 474
Likes: 0
From: Stockport
Post

Have to use IIS unfortunately. Need it for ASP and we're using custom COM components as well...

Reply
Old Jun 21, 2002 | 03:58 PM
  #12  
stevem2k's Avatar
stevem2k
Scooby Regular
 
Joined: Sep 2001
Posts: 4,670
Likes: 0
From: Kingston ( Surrey, not Jamaica )
Post

Tie it all down then. Run a firewall in front of it - if you are tight on time or the beancounters are having an off day, then a smoothwall will be enough. Don't use a software firewall on anything like a production machine.

Steve
Reply
Old Jun 21, 2002 | 04:24 PM
  #13  
kryten's Avatar
kryten
Scooby Regular
 
Joined: May 2000
Posts: 869
Likes: 0
Post

1) Patch IIS
2) Get a firewall (you could use a software one, hardware is better)
3) Patch IIS (there will be a new one by now!)

Bascially, you want to disable everything you're not going to be using. If this is your first attempt then I would suggest you leave the machine on the net for a week or so BEFORE you add anything even remotely important to it!

Also, make sure its not connected to the rest of your network - if it is then pay someone who knows what they're going (because you'll need a DMZ for it and its SO easy to get it wrong).

If you're determined to DIY then Securing win2k/NT servers for the Internet by O'Reilly is a must have as is the IIS Lockdown tool from MS (does a lot of the stuff for you).
Reply
Old Jun 21, 2002 | 05:11 PM
  #14  
ChrisB's Avatar
ChrisB
Moderator
 
Joined: Dec 1998
Posts: 23,573
Likes: 0
From: Staffs
Post

Baseline Security Scanner from MS is very handy as well.
Reply
Old Jun 21, 2002 | 05:20 PM
  #15  
stevem2k's Avatar
stevem2k
Scooby Regular
 
Joined: Sep 2001
Posts: 4,670
Likes: 0
From: Kingston ( Surrey, not Jamaica )
Post

As is the off button.

Reply
Old Jun 21, 2002 | 06:44 PM
  #16  
Rob Walker's Avatar
Rob Walker
Thread Starter
Scooby Regular
 
Joined: Nov 1999
Posts: 474
Likes: 0
From: Stockport
Post

A hardware firewall is out of the question at the moment. The server is in a remote location at the moment. We'll possibly move it in house in the future depending on how things go.

Anyone got any suggestions for a good (cheap) firewall. Personally I use Sygate at the moment and was thinking of using that. Not too keen on Zonealarm cos I've had a few problems with that in the past.

Cheers for all the help
Rob
Reply
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
KAS35RSTI
Subaru
27
Nov 4, 2021 07:12 PM
Brzoza
Engine Management and ECU Remapping
1
Oct 2, 2015 05:26 PM
BLU
Computer & Technology Related
11
Oct 2, 2015 12:53 PM
Mad Hammer
Subaru Parts
2
Sep 29, 2015 08:15 PM
The Joshua Tree
Computer & Technology Related
30
Sep 28, 2015 02:43 PM


Thread Tools
Search this Thread

All times are GMT +1. The time now is 04:33 PM.