WSE12 Disable Remote Web Access

orgetorix

Reputable
Jun 16, 2015
30
0
4,530
How can I disable Remote Web Access on Windows Server 2012 Essentials? I created a dynamic DNS through duckdns.org and when I connect, I get a page to connect to my home server. I then remembered doing something similar many moons using noip.com.

Anyway, there seems to be some interference, and I would like to not have this feature enabled any longer.

Thanks!
 
More the question would be how did you manage to make it work so you can get remote access to your server at all. People come here all the time asking how to get remote access and what port forwarding rules they need because by default there is no access to any machine in your network.

Now if you have directly attached you machine to a modem with no router in between then your machine is directly on the internet and any port that is open on the machine can be attacked. This is not a recommenced installation because you always risk a bug in something as complex as a server OS. You can restrict access with firewall rules but it assumes there is no bug that can bypass it.

A simple router in the path with a default configuration prevent any access to the server from the internet.
 

orgetorix

Reputable
Jun 16, 2015
30
0
4,530
You know what? It's been so long that I have no idea how I got it working, past the standard "followed the wizard" routine. I know there was some router settings involved as well, but the first thing I did in troubleshooting this was to reset my router to factory settings.

I also ahve replaced my modem since the initial setup, going from renting from my ISP to rolling my own.
 
For best results, disable it on two places:
- first, on your router, disable port-forwarding of ports 80 and 443 to your server. This is enough
- on your WSE2012: Open Dashboard, click on Settings on the top right, Anywhere Access, and work your way down from here (I don't have it enabled on my WSE, so don't know how to disable it).
 

orgetorix

Reputable
Jun 16, 2015
30
0
4,530
That's the crazy part now. Since i reset my router to factory, there are no Port Forwarding / Port Triggering rules or Default DMZ Server set. If I shut down the WSE12 machine I can no longer (obviously) connect. Is there a way in WSE12 to disable this feature?
 

orgetorix

Reputable
Jun 16, 2015
30
0
4,530


Thank you. I will try this a bit later today. I poked around in a few settings and could find a place to configure or repair but not disable or turn off.
 

orgetorix

Reputable
Jun 16, 2015
30
0
4,530


Here are a couple screenshots from my current router settings. I'm not sure how it even connects from outside my network, which is what I am trying to eliminate.

jb5v2d.jpg

2646iqw.png

 

orgetorix

Reputable
Jun 16, 2015
30
0
4,530


I am testing from my work network that is completely separate from where this machine lives. I ran a scan on all common ports from yougetsignal.com and only ports 80 and 443 are open. With these settings I still get the following:

dw5ipu.png
 


What is shown if you change "Service Name" from FTP to eg WWW/HTTP?
 

orgetorix

Reputable
Jun 16, 2015
30
0
4,530


There are no entries for that either. I guess I will try to find another router and see what happens. After that I'll probably refresh the server completely.