Corso referenti S.I.R.A. – Modulo 2 Windows Client & Server Security 20/11 – 27/11 – 05/12 11/12 – 13/12 (gruppo 1) 12/12 – 15/12 (gruppo 2) Cristiano Gentili, Massimiliano Viola (CSIA)
Windows firewall: la difesa sul client
Lelenco delle eccezioni
Modificare la visibilità del servizio
Definire le eccezioni (1)
Definire le eccezioni (2)
Eccezioni diversificate per connessione
Definire le eccezioni per connessione (1)
Definire le eccezioni per connessione (2)
Logging dellattività
Deployment/Configuration Deploying Windows Firewall Settings Windows Firewall INF file %windir%\Inf\Netfw.inf Using Netsh To allow incoming traffic on TCP port 80 netsh firewall add portopening protocol=TCP port=80 name=Web Server (TCP 80) mode=ENABLE scope=SUBNET profile=DOMAIN Using Group Policy
Firewall via GPO
Il Futuro Windows Firewall in Windows Vista and Windows Server "Longhorn" enhancements Supports filtering for both incoming and outgoing traffic Firewall filtering and Internet Protocol security (IPsec) exceptions can be configured for Active Directory accounts and groups, source and destination IP addresses, IP protocol number, source and destination Transmission Control Protocol (TCP) and User Datagram Protocol (UDP) ports, all or multiple TCP or UDP ports, specific types of interfaces, Internet Control Message Protocol (ICMP) and ICMP for IPv6 (ICMPv6) traffic by Type and Code, and for services
More info Windows Firewall Network Ports Used by Key Microsoft Server Products Security/ref_net_ports_ms_prod.mspx