Tom's Hardware > Forum > Windows 2000/NT > Windows 2000/NT General Discussion > How to block all traffic but SQL Server

How to block all traffic but SQL Server

Forum Windows 2000/NT : Windows 2000/NT General Discussion - How to block all traffic but SQL Server

Tom's Hardware: Over 1.4 million members in 6 different countries available to answer all your high-tech questions. Sign up now! Its free!
Word :    Username :           
 

Archived from groups: microsoft.public.win2000.security (More info?)

 

We are installing a new server, and it is suppose to be used ONLY for SQL
SERVER 2000, how can I block all traffic and all ports and allow only the
ports used by SQL Server?
Norton Security is not working right, some time it blocks legit queries and
access to SQL Server.
Thanks, I have to choose our next firewall program and I dont know the best
for this job.

Sponsored Links
Register or log in to remove.

Archived from groups: microsoft.public.win2000.security (More info?)

 

Of course layering things is best. However, on the SQL machine itself
you can also define use of IPsec in a filtering mode, where all traffic is
rejected and then you permit the SQL ports tcp 1433/1434 to only the
source IPs that should have any access. If the machine is W2k3 then
you should be at SP1 and you could look at using the firewall and
setting the machine up by use of the new security configuration wizard
(and after that layer in the mentioned IPsec filtering if desired).

--
Roger Abell
Microsoft MVP (Windows Security)
MCSE (W2k3,W2k,Nt4) MCDBA
"hug gozz" <hhugg@hotmil.com> wrote in message
news:1117854156.ff0870e2e0806fe4c541b391cf70b99d@teranews...
> We are installing a new server, and it is suppose to be used ONLY for SQL
> SERVER 2000, how can I block all traffic and all ports and allow only the
> ports used by SQL Server?
> Norton Security is not working right, some time it blocks legit queries
and
> access to SQL Server.
> Thanks, I have to choose our next firewall program and I dont know the
best
> for this job.

Reply to Anonymous

Archived from groups: microsoft.public.win2000.security (More info?)

 

On Sat, 04 Jun 2005 03:02:36 GMT, hug gozz <hhugg@hotmil.com> wrote:

>We are installing a new server, and it is suppose to be used ONLY for SQL
>SERVER 2000, how can I block all traffic and all ports and allow only the
>ports used by SQL Server?

Depends on whether or not this is behhind a firewall.

>Norton Security is not working right, some time it blocks legit queries and
>access to SQL Server.

You shouldn't use a wokstation or home security product on a server
anyway.

>Thanks, I have to choose our next firewall program and I dont know the best
>for this job.

Hardware firewall is best. If you use Server 2003 you have one built
in that does fine. Kerio seems to work okay on servers from what I've
tried. There is also a server version of Symantec's products, though
it isn't free.

Jeff

Reply to Anonymous

Archived from groups: microsoft.public.win2000.security (More info?)

 

jeff.nospam@zina.com (Jeff Cochran) wrote in
news:42a8ca08.925048812@msnews.microsoft.com:

You are right, seems like I have to ask for Server 2003 upgrade, we have
Windows Advanced Server 2000 with SP4 and SQL Server 2000 with SP3.

Using Tiny Firewall, GFI Network Monitor and GFI LANGuard Security Scanner.
Doing pretty good, but still want to safer. I will be rewieing Keri to see
what it has. Norton Security used at the beginning as we have no budget,
but discarded almost the same day.
Panda´s Server was to complicated, I spent too much time trying to figure
everything up.

Thanks for the answers.

Reply to Anonymous

Archived from groups: microsoft.public.win2000.security (More info?)

 

As Roger said you can block everything except SQL
trivially with the built-in IPSec -- and it's built-into
every OS workstation or server since Win2000.

But the origianal question may not be precisely what
is desired if this is to be a domain machine and/or
use integrated security for accessing the data, allow
management tool access, or other resource management.

There are more ports to open but they can be open to
specific addresses.

--
Herb Martin, MCSE, MVP
Accelerated MCSE
http://www.LearnQuick.Com
[phone number on web site]

"humberto gonzalez" <hhugg@hotmil.com> wrote in message
news:1117940318.402bd878cf32f3c958a3dde75c47ed43@teranews...
> jeff.nospam@zina.com (Jeff Cochran) wrote in
> news:42a8ca08.925048812@msnews.microsoft.com:
>
> You are right, seems like I have to ask for Server 2003 upgrade, we have
> Windows Advanced Server 2000 with SP4 and SQL Server 2000 with SP3.
>
> Using Tiny Firewall, GFI Network Monitor and GFI LANGuard Security
Scanner.
> Doing pretty good, but still want to safer. I will be rewieing Keri to see
> what it has. Norton Security used at the beginning as we have no budget,
> but discarded almost the same day.
> Panda´s Server was to complicated, I spent too much time trying to figure
> everything up.
>
> Thanks for the answers.

Reply to Anonymous
Tom's Hardware > Forum > Windows 2000/NT > Windows 2000/NT General Discussion > How to block all traffic but SQL Server
Go to:

There are 1163 identified and unidentified users. To see the list of identified users, Click here.

Please mind

You are about to answer a thread that has been inactive for more than 6 months.
If you still wish to proceed, please ensure that your posting is original and does not duplicate or overlap any prior responses to this thread.

Add a reply Cancel
Sponsored links
  • Ask the community now
  • Publish
Ad
They won a badge
Join us in greeting them