IPSec Packet Filter(s) and SMS 2.0 Network Monitor

B

Bill Tomlinson

I am interested in applying the IPSec Packet filters that are recommended in
the TechNet Security section: "Hardening Specific Server Roles - ch7."

I have looked up all the ports that are "Listening" on my default W2k server
(using portqry), and there are many that will be filtered out if I use the
filters suggested.

I would like to determine a methodology for deciding which 'additional'
ports I will need to "allow" through my IPSec packet filter.

For example my tape backup software has a centralized console that
communicates to the other backup-clients on my other servers to allow them
to be managed from one source. I am assuming that this software uses
'ports' to communicate over the network. If this is a true assumption then
could I use the network monitor in SMS 2.0 to capture this communication,
and determine from the captured packets which port(s) it is using?

Are there tools, techniques, strategies that you can recommend to manage
this process of "mapping" out the ports you need to create filters for?

Thanks

BT
 
K

Karl Levinson [x y] mvp

IMHO this is best done using a technology that logs packets. Windows
implementation of IPSec does not do this, which is why I think it is not the
best choice for doing what you're trying to do, esp. if you don't already
know the ports you need.

Having said that, you can either choose a different packet filtering
technology that does do logging, or if you prefer, you can use Windows
Network Monitor or a sniffer to monitor traffic prior to filtering.

http://securityadmin.info/faq.htm#sniffer
http://securityadmin.info/faq.htm#firewall
http://securityadmin.info/faq.htm#ipsec
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top