You didn't plan to expose your PDC to the Internet---I hope.  That's my
first recommendation.  

Assuming that's the case, then many of the suggestions you would find on
this list wouldn't be applicable.

If you do need to authenticate users and provide NT services over the
Internet, then you pretty much have to do a VPN, with a firewall in front of
everything.  Anything else would be asking for it.

Hal Rottenberg             | Hewlett-Packard
Technical Support Engineer | Phone: +1-404-774-4041
Internet Security Division | Email: [EMAIL PROTECTED]

Web: http://www.hp.com/security

> -----Original Message-----
> From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]
> Sent: Friday, September 15, 2000 12:52 PM
> To: Noonan, Wesley; [EMAIL PROTECTED]
> Cc: [EMAIL PROTECTED]
> Subject: RE: Windows 2k Advanced Server Hardening
> 
> 
> Ok,
> 
> Let's say I am deploying a PDC, and I want to allow users to 
> log on to the 
> domain, but that is about it..
> 
> /mark
> 
> At 11:44 AM 9/15/00 -0500, Noonan, Wesley wrote:
> >Advanced TCP/IP properties, options tag. Start filtering 
> ports and setup
> >IPSec. Disable all unnecessary services. Depends on what you 
> want it to do,
> >to know what services to disable. The obvious one is the 
> server service. HTH
> >
> >Wes Noonan, MCP+I/MCSE/MCT/CCNA/NNCSS
> >Senior QA Rep
> >(713) 918-2412
> >BMC Software, Inc.
> >[EMAIL PROTECTED]
> >http://www.bmc.com
> >
> >  -----Original Message-----
> >From:   [EMAIL PROTECTED] 
[mailto:[EMAIL PROTECTED]]
>Sent:   Friday, September 15, 2000 11:37
>To:     [EMAIL PROTECTED]
>Cc:     [EMAIL PROTECTED]
>Subject:        Windows 2k Advanced Server Hardening
>
>How would one go about hardening a Windows 2k Advanced Server??
>
>
>Where would one start???
>
>
>/cheers
>
>/mark
>
>-
>[To unsubscribe, send mail to [EMAIL PROTECTED] with
>"unsubscribe firewalls" in the body of the message.]

-
[To unsubscribe, send mail to [EMAIL PROTECTED] with
"unsubscribe firewalls" in the body of the message.]
-
[To unsubscribe, send mail to [EMAIL PROTECTED] with
"unsubscribe firewalls" in the body of the message.]

Reply via email to