Security Basics mailing list archives

re: win2k firewall


From: H C <keydet89 () yahoo com>
Date: Mon, 6 Jan 2003 12:27:13 -0800 (PST)

anyone can recommend software firewall for win2k
adv. 
server ? it is planed to be used as web server

Web servers, even those on Win2K, shouldn't need or
have a firewall.  This is true for several reasons...

1.  What is the purpose of running a web server on a
firewall?  Does that make sense?  No, of course not.

2.  If you're concerned about restricting ports, why
not simply disable or remove all unnecessary services?
 You're going to configure the firewall to allow port
80 (and maybe 443) anyway, right?  So why not simply
save yourself some hard drive space, memory, as well
as admin and management headaches by simply turning
off everything else?  There's no reason you need to
have the Server service running, for example, on a web
server.  In fact, you don't even need NetBIOS/NetBEUI
installed.

So...if you turn off all the services that you don't
need, and you only have ports 80 (and 443, maybe)
open, then what would be the point of the firewall?


__________________________________________________
Do you Yahoo!?
Yahoo! Mail Plus - Powerful. Affordable. Sign up now.
http://mailplus.yahoo.com


Current thread: