Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

A few questions re:ipsec

Thread Tools
 
Search this Thread
 
Old 06 July 2004, 02:42 PM
  #1  
Stueyb
Scooby Regular
Thread Starter
 
Stueyb's Avatar
 
Join Date: May 2002
Posts: 1,893
Likes: 0
Received 0 Likes on 0 Posts
Default A few questions re:ipsec

Hi guys n gals.

Just looking to secure a internet server and have done most stuff, but i want to be able to remote admin it, but securely.

So what are my options ?

1. Use Remote Assistance/etc. Is it secure ?
2. Use openSSh, handy for command line stuff

and 2 questions that im really interested in .Does IPSEC effectively do what the encrypt side of ssh does? If not what does it do?

Also securing the machine. Its a w2k machine and I don't know any free firewalls that are useful so someone mentioned RRAS as an elementary way of doing it. What does it do and what does itinvolve ?
Old 06 July 2004, 06:52 PM
  #2  
Puff The Magic Wagon!
Moderator
Support Scoobynet!
iTrader: (2)
 
Puff The Magic Wagon!'s Avatar
 
Join Date: May 2000
Location: From far, far away...
Posts: 16,978
Received 15 Likes on 9 Posts
Default

Get an old P2 & run something like IPCOP or SmoothWall on it as your Firewall. Cheap as chips & good hardware firewall on a separate machine to the webserver.
Old 06 July 2004, 11:03 PM
  #3  
BlkKnight
Scooby Regular
 
BlkKnight's Avatar
 
Join Date: Feb 2004
Location: High Wycombe
Posts: 3,763
Likes: 0
Received 0 Likes on 0 Posts
Default

If you really MUST have a win2k box facing the WWW i've created a good (ish) - IPSEC configuration.

It blocks pretty much all incomming except for www and Terminal services client.

you can quikly switch on and off FTP access too (to allow passive connections from behind other firewalls)
Stick up your e-mail and i'll send you the file.

For a small fee I could toughen up other security aspects of your server for ya.

Given that I really DO NOT recommend having a commercial windows based webserver directly connected to the big bad www. As a minimum www traffic should be routed through a non-windows firewall.
Old 06 July 2004, 11:33 PM
  #4  
Stueyb
Scooby Regular
Thread Starter
 
Stueyb's Avatar
 
Join Date: May 2002
Posts: 1,893
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by BlkKnight
If you really MUST have a win2k box facing the WWW i've created a good (ish) - IPSEC configuration.

It blocks pretty much all incomming except for www and Terminal services client.

you can quikly switch on and off FTP access too (to allow passive connections from behind other firewalls)
Stick up your e-mail and i'll send you the file.

For a small fee I could toughen up other security aspects of your server for ya.

Given that I really DO NOT recommend having a commercial windows based webserver directly connected to the big bad www. As a minimum www traffic should be routed through a non-windows firewall.
Hi there,

My email is stuart@novellguy.co.uk.

Ok explanation time. Basically, as puff knows im setting up a totally new internet concept. I want to keep costs down so I know Windows administration quite well, admin a 100 user site day to day. So I realise Unix/Linux would be a lot better but I can secure a W2K a lot more easily thank a linux machine because I dont know linux. Also the firewall is an issue because its sitting in a certain texas DC in a rack. I can only really afford the one machine at present.

I may take up the offer of the tightening but it is pretty secure but a bit of peer review never hurt anyone

Ill see how things go
Old 07 July 2004, 12:06 AM
  #5  
BlkKnight
Scooby Regular
 
BlkKnight's Avatar
 
Join Date: Feb 2004
Location: High Wycombe
Posts: 3,763
Likes: 0
Received 0 Likes on 0 Posts
Default

sent - as i said in the e-mail make sure you have physical access to the box before running it. Ideally run it on a test box you can scrap if needbe

It's configured to allow incomming "terminal services client". VNC and other stuff like PC anwahere will not work.
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
KAS35RSTI
Subaru
27
04 November 2021 07:12 PM
slimwiltaz
General Technical
20
09 October 2015 07:40 PM
IanG1983
Wheels, Tyres & Brakes
2
06 October 2015 03:08 PM
Brzoza
Engine Management and ECU Remapping
1
02 October 2015 05:26 PM
the shreksta
Other Marques
26
01 October 2015 02:30 PM



Quick Reply: A few questions re:ipsec



All times are GMT +1. The time now is 04:00 PM.