Can RRAS packet filtering somehow replace a local software firewall?

  • Thread starter Thread starter Vince C.
  • Start date Start date
V

Vince C.

Hi, all.

I mean "can I setup a smart configuration of Packet Filtering in RRAS to
achieve the same level of protection as a software firewall such as Kerio
Personal Firewall?

The main reason for this question is I played a little with packet filtering
to prohibit outbound traffic to AD servers, for instance, like
doubleclick.net, fastclick.com, aso. It is a global solution that will fit
all of my workstations in a LAN. With a software firewall like Kerio it is
much more complicated and all I could achieve simply was to deny access to
those servers from the local machine itself (i.e. the server machine on
which Kerio was installed). Now I'm considering replacing my PFW engine with
rules defined in RRAS Packet filtering.

The other point is I have a workstation in the LAN that can sometimes act as
a server (it's a gaming machine with Unreal Tournament). With my personal
firewall I have to define rules that I must enable whenever I'm playing
otherwise outbound TCP/UDP packets are rejected. But these rules are like
wide open doors for I have to enable almost all ports above 1024 due to NAT
outbound traffic. NAT chooses random port values above 1024 to map ports on
LAN workstations. And there is SQL Server, which uses port 1433.

I'd like to have rules that allow incoming/outgoing traffic on specific
ports to/from my gaming machine only when I'm playing. I don't like to
create loose rules that could allow anyone to hack my server when I'm
playing. I think I understand I can achieve this with packet filtering.
(after all a firewall is a smart packet filter, isn't it?)

So is it a good idea or should I still consider leaving my firewall active
and enabled? I'd prefer not to switch to ISA server.

Thanks for any hint/suggestion.
 
Thanks, Benny. But I'm not sure IPSec and VPN answer my question. I'd have liked
to know if I could safely remove my software firewall and use RRAS IP packet
filtering instead. Besides I don't have Proxy server and I'm using NAT - again
from RRAS.

Next I can't use any tunneling form for gaming and incoming connections since
Unreal Tournament doesn't support it. Besides I can't tell anonymous players who
would connect to my gaming server to configure tunneling to connect...

All I wanted to know was if I could safely setup RRAS IP filtering policies to
replace my software firewall. Is it a viable solution and is it secure enough?

Vince C.
 
Benny Fu said:
Dear Vince,

Thank you for your reply.
[...]
Hope it clears your concerns.

Well... in fact, no. But I realized I should have posted to
microsoft.public.win2000.ras_routing since my question relates to RRAS
packet filtering capabilities.

Thanks again.

Vince C.
 
Dear Vince,

Thank you for your reply. If there is anything we can do to be of
assistance with technical resolutions in the future, please feel free to
let us know and we will try our best to help you enjoy using our products.

Thanks again and have a good day!

Regards,

Benny Fu
Microsoft Online Partner Support
Microsoft Corporation
Get Secure! – www.microsoft.com/security

This posting is provided "AS IS" with no warranties, and confers no rights.

--------------------
| From: "Vince C." <[email protected]>
| References: <#[email protected]>
<[email protected]>
<[email protected]>
<[email protected]>
| Subject: Re: Can RRAS packet filtering somehow replace a local software
firewall?
| Date: Thu, 14 Aug 2003 00:24:09 +0200
| Lines: 18
| X-Priority: 3
| X-MSMail-Priority: Normal
| X-Newsreader: Microsoft Outlook Express 6.00.2800.1158
| X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
| Message-ID: <[email protected]>
| Newsgroups: microsoft.public.win2000.advanced_server
| NNTP-Posting-Host: 217-117-48-96.teledisnet.be 217.117.48.96
| Path: cpmsftngxa06.phx.gbl!TK2MSFTNGP08.phx.gbl!tk2msftngp13.phx.gbl
| Xref: cpmsftngxa06.phx.gbl microsoft.public.win2000.advanced_server:10601
| X-Tomcat-NG: microsoft.public.win2000.advanced_server
|
| "Benny Fu" <[email protected]> a écrit dans le message de
| | > Dear Vince,
| >
| > Thank you for your reply.
| >
| [...]
| > Hope it clears your concerns.
|
| Well... in fact, no. But I realized I should have posted to
| microsoft.public.win2000.ras_routing since my question relates to RRAS
| packet filtering capabilities.
|
| Thanks again.
|
| Vince C.
|
|
|
 
Back
Top