19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Communications Remarks<br />

____________________________________________________________________ .........................................<br />

S 5.43 Secure configuration of TCP/IP network<br />

services under Windows NT<br />

Initiation responsibility: Head of <strong>IT</strong> Section, <strong>IT</strong> Security Management<br />

Implementation responsibility: Administrators<br />

TCP/IP<br />

When installing the TCP/IP protocol, properties can be set with the control<br />

panel option "Network". Given that the computer concerned has more than one<br />

network card and/or remote access via RAS is installed (Remote Access<br />

Server, see S 5.41 Secure configuration of remote access under Windows NT),<br />

attention must be paid here, that routing between these cards, i.e. between the<br />

remote access interface and the network card, can be switched on via the<br />

"Enable IP-Forwarding" option under the register card "Routing". As a rule,<br />

this option should not be activated on computers which have a connection to<br />

an external network such as the Internet, since this will allow external<br />

computers transparent access to the local network.<br />

In version 4.0 filtering of data traffic via TCP/IP can be achieved to a certain<br />

extent. This can be done by choosing the "Advanced" option under the register<br />

card "IP address" and selecting the "Enable Security" option in the opened<br />

window. By choosing the "Configure" option the permitted or, as the case may<br />

be, locked TCP and UDP ports and IP protocols for single network cards can<br />

be selected. <strong>The</strong> values to be entered here should be selected according to the<br />

necessary function and the given security requirements. A security concept for<br />

the use of Internet services should exist for computers with external<br />

connections. Considerations to be taken here should be similar to those taken<br />

when installing a firewall (see <strong>Baseline</strong> <strong>Protection</strong> module 7.3 Firewall, in<br />

particular S 2.76 Selection and Implementation of suitable filter rules).<br />

FTP (File Transfer Protocol)<br />

An FTP server will be set up during installation of TCP/IP under version 3.51;<br />

in version 4.0 the FTP server can be installed as part of the installation of<br />

Peer-Web-services. If the FTP server service is executed on a Windows NT<br />

system, other <strong>IT</strong> systems can create a connection with this Windows NT<br />

system as clients via the FTP service programme and thus transfer files. Users<br />

who create a connection with the FTP server are authenticated under Windows<br />

NT via their user account and are granted access dependent upon their user<br />

profile. For this reason, it is necessary to install the FTP server on a NTFS<br />

partition so that files and directories made accessible by FTP can be protected.<br />

Following installation the FTP server must be configured before it can be<br />

operated. <strong>The</strong> configuration settings can lead to one of the following<br />

situations:<br />

- No anonymous FTP connections are permitted. In this case, each user must<br />

enter a username and password valid under Windows NT.<br />

- Anonymous users as well as users under Windows NT can make a<br />

connection. In this case a user can choose between an anonymous port and<br />

a connection via username and password under Windows NT.<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!