J
Jerome Schnitzler
----- Original Message -----
From: "Kevin D. Goodknecht [MVP]" <[email protected]>
Newsgroups: microsoft.public.win2000.dns
Sent: Tuesday, November 25, 2003 2:54 AM
Subject: Re: ZONE Transfer to BIND 8/9
I know that ... this is a server only system ... my problem is ... that I
opened port 53 for all connections and security is turned off. Still this
port is filtered. Is there an option in the local security ruleset which
might still switched on?
From: "Kevin D. Goodknecht [MVP]" <[email protected]>
Newsgroups: microsoft.public.win2000.dns
Sent: Tuesday, November 25, 2003 2:54 AM
Subject: Re: ZONE Transfer to BIND 8/9
In
If IPSec is set to "require" security For all IP traffic, it will always
require security using Kerberos trust and will NOT allow unsecured
communication with untrusted clients.
Try changing it to request security if you must have IPSec to the internet.
So for as worrying about worms since this server is connected directly to
the internet use a good firewall and do not allow it to be used as a
workstation. Any one using this server as a workstation, if they do execute
a virus or worm that nasty little bug has the same rights as the user. Never
browse the internet from this machine. If you have an internal network using
this as a gateway I would highly recommend using a Proxy server that scans
the data stream. There are good ones that are very reasonably priced such as
Wingate and Winroute that do a very good job of protecting your internal
network. Most will give you a thirty day trial.
Is TCP/IP filtering turned on?
Do you have any ports open above 1024?
TCP/IP filtering on the interface closes both incoming and outgoing ports it
does not allow for port redirection for outgoing connections. Instead of the
filtering on the interface get a firewall or use packet filtering in RRAS.
I know that ... this is a server only system ... my problem is ... that I
opened port 53 for all connections and security is turned off. Still this
port is filtered. Is there an option in the local security ruleset which
might still switched on?