Learn to protect IIS Server Service Account Security

Source: Internet
Author: User

Unless absolutely required, do not run the IIS server service in the security context of the domain account. If the physical security of the IIS server is damaged, the domain account password can be easily obtained by dumping the local security authorization (LSA) secret.

Use IPSec filter to block ports

The Internet Protocol Security (IPSec) filter can provide an effective way to enhance the security level required by the server. We recommend that you use this option in a high-security environment to further reduce the number of vulnerable IIS servers.

For more information about using IPSec filters, see other Member Server enhancement processes in the module.

The following table lists all IPSec filters that can be created on the IIS server in the advanced security environment defined in this Guide.

IPSec network communication diagram of IIS server

 
 
  1. Service protocol source port target port source address target address operation Image
  2. All me mom servers of one point Client are allowed to be
  3.  
  4. Terminal Services TCP all 3389 all ME allowed is
  5.  
  6. Domain Member all ME Domain controllers allow
  7.  
  8. Domain Member all ME Domain controllers allow
  9.  
  10. HTTP Server TCP all 80 all ME allowed is
  11.  
  12. HTTPS Server TCP all 443 all ME allowed is
  13.  
  14. All Inbound Traffic All ME prohibited is

All the rules listed in the IPSec network communication diagram of the IIS server should be mirrored. This ensures that any network communication that enters the server can also be returned to the source server.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.