设为首页 收藏本站
查看: 519|回复: 0

[经验分享] Lock down Windows Server 2003 with the Security Configuration Wizard

[复制链接]

尚未签到

发表于 2016-5-19 07:03:55 | 显示全部楼层 |阅读模式
  http://articles.techrepublic.com.com/5100-10878_11-6081763.html
Takeaway: If you've been looking for a way to standardize and simplify security settings for your Windows Server 2003 servers, don't overlook the Security Configuration Wizard. Mike Mullins has the details in this edition of Security Solutions.
  Many organizations struggle with implementing the proper security features on a new Windows Server 2003 installation, and some just add security as needed. As far as resources go, there are multiple sources for checklists and guides available, including SANS, NSA, NIST, and a host of others. However, rather than reading through hundreds of pages of documentation and creating custom security templates, there's an easier way—the Security Configuration Wizard.
  This wizard contains an XML database that includes every service, feature, and administration option for every different server deployment type. Regardless of whether you're deploying a DNS, Exchange, File and Print, Domain Controller, or any other Windows server, this tool has the settings you need to lock it down.
Run the wizard
  The main purpose of this wizard is to implement role-based security on Windows Server 2003. By defining the server's role on the network, you can disable unnecessary services, block unused ports, implement additional address or security restrictions for ports necessary for operation, disable unnecessary IIS Web extensions, and restrict access to server message block (SMB), LanMan, and Lightweight Directory Access Protocol (LDAP) services.
  You must have Windows Server 2003 Service Pack 1 installed to run this wizard. To access the wizard, go to Start | All Programs | Administrative Tools | Security Configuration Wizard (Scw.exe).
  When you first run the tool, it will prompt you to start or install any network applications (e.g., IIS, Exchange, SQL, etc.) that the server will use, so it can define the server role and apply the proper security settings. The wizard will also ask whether you want to create a new security policy, edit an existing policy, apply a policy, or roll back a policy. For this example, we're using this tool after initial installation, so select Create A New Security Policy.
Define the role
  At this point, you can select a predefined role for your server from the wizard's security configuration database. After you select the server role, the wizard will prompt you to select the client features, additional administrative options, additional services (for non-Microsoft applications), and any special handling for these services.
  Now, let's take a look at the different sections of the Security Configuration Wizard.
Network security
  This section configures inbound ports using the built-in Windows Firewall. The tool bases the displayed settings on the roles and administration options that you've selected. If your organization uses IPSec, you can add further restrictions to access IP services and ports as well as configure encryption for port traffic using IPSec.
Registry settings
  This section configures protocols used to communicate with computers on the network. If you have legacy Windows systems operating on your network (pre-Windows 2000), these systems create an additional vulnerability to password-cracking and man-in-the-middle attacks, and they require special configuration to interoperate with Windows Server 2003. You can adjust the security settings of SMB and LDAP services as well as inbound/outbound authentication protocols for these legacy systems.
Audit policy
  This section configures the auditing of the server based on your organization's auditing policy. The Audit Policy Editor allows you to configure the server to not audit any events, audit only successful events, or audit both successful and unsuccessful events.
  Warning: If you use the wizard to apply the built-in audit security template to set the System Access Control Lists (SACLs), you cannot remove these settings through the rollback feature.
Internet Information Services
  If this server will function as an IIS server, the wizard will prompt you to configure the security for the Web server. You can select the Web service extensions used for dynamic content, virtual directories used for your Web server, and allow or deny anonymous users from accessing Web site content.
Final thoughts
  While some people might still prefer the pre-Windows Server 2003 method of securing their servers, the Security Configuration Wizard provides a powerful and easy opportunity to create a role-based security template that you can apply consistently to every server you own. If you've been looking for a way to standardize and simplify security settings for your Windows Server 2003 servers, don't overlook the Security Configuration Wizard.
Miss a column?
  Check out the Security Solutions Archive, and catch up on the most recent editions of Mike Mullins' column.
  Worried about security issues? Who isn't? Automatically sign up for our free Security Solutions newsletter, delivered each Friday, and get hands-on advice for locking down your systems.
  Mike Mullins has served as an assistant network administrator and a network security administrator for the U.S. Secret Service and the Defense Information Systems Agency. He is currently the director of operations for the Southern Theater Network Operations and Security Center.

  

运维网声明 1、欢迎大家加入本站运维交流群:群②:261659950 群⑤:202807635 群⑦870801961 群⑧679858003
2、本站所有主题由该帖子作者发表,该帖子作者与运维网享有帖子相关版权
3、所有作品的著作权均归原作者享有,请您和我们一样尊重他人的著作权等合法权益。如果您对作品感到满意,请购买正版
4、禁止制作、复制、发布和传播具有反动、淫秽、色情、暴力、凶杀等内容的信息,一经发现立即删除。若您因此触犯法律,一切后果自负,我们对此不承担任何责任
5、所有资源均系网友上传或者通过网络收集,我们仅提供一个展示、介绍、观摩学习的平台,我们不对其内容的准确性、可靠性、正当性、安全性、合法性等负责,亦不承担任何法律责任
6、所有作品仅供您个人学习、研究或欣赏,不得用于商业或者其他用途,否则,一切后果均由您自己承担,我们对此不承担任何法律责任
7、如涉及侵犯版权等问题,请您及时通知我们,我们将立即采取措施予以解决
8、联系人Email:admin@iyunv.com 网址:www.yunweiku.com

所有资源均系网友上传或者通过网络收集,我们仅提供一个展示、介绍、观摩学习的平台,我们不对其承担任何法律责任,如涉及侵犯版权等问题,请您及时通知我们,我们将立即处理,联系人Email:kefu@iyunv.com,QQ:1061981298 本贴地址:https://www.yunweiku.com/thread-218826-1-1.html 上篇帖子: 关闭Windows 2003/2008中IE增强的安全配置 下篇帖子: windows 2003 远程桌面关闭 运行程序退出解决
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

扫码加入运维网微信交流群X

扫码加入运维网微信交流群

扫描二维码加入运维网微信交流群,最新一手资源尽在官方微信交流群!快快加入我们吧...

扫描微信二维码查看详情

客服E-mail:kefu@iyunv.com 客服QQ:1061981298


QQ群⑦:运维网交流群⑦ QQ群⑧:运维网交流群⑧ k8s群:运维网kubernetes交流群


提醒:禁止发布任何违反国家法律、法规的言论与图片等内容;本站内容均来自个人观点与网络等信息,非本站认同之观点.


本站大部分资源是网友从网上搜集分享而来,其版权均归原作者及其网站所有,我们尊重他人的合法权益,如有内容侵犯您的合法权益,请及时与我们联系进行核实删除!



合作伙伴: 青云cloud

快速回复 返回顶部 返回列表