A special care must be taken to protect the gateway host itself. Current Comsocks version doesn't provide such a protection. Please follow some general practices to maximize your Windows security:
- Always DISABLE file and printer sharing. Please see the FAQ q5.
- Always select strong admin and user passwords for Windows NT/2000. Change them regularly.
- Set a "RestrictAnonymous" REG_DWORD value to 1 in "HKLM\CurrentControlSet\Control\lsa" registry tree in Windows NT 4 to disallow anonymous access.
- Do NOT run any unnecessary server software (eg. IIS) other than Comsocks.
- Only install and run minimal applications and services in the gateway host. Disable unnecessary services.
- In Windows NT, enable TCP/IP security and filtering under Microsoft TCP/IP Properties (Control Panel->Network->Protocol->TCP/IP->Advanced->Enable Security). Only allow those ports and protocols necessary to the function of the gateway. You can block TCP/UDP ports 135-139 for NETBIOS access(file sharing).
- In Windows NT, disable Guest account.
- In Windows NT, remove Everyone from the Access This Computer From The Network User Right under "Policies->User Rights" in User Manager.
- Apply the most recent Service Packs and security fixes.
- Enable Auditing in Windows NT.
- Install third-party firewall software to protect the gateway (e.g. BLACKICE, Nortan Internet Securty, etc...).
- Install third-party anti-virus software.
- Restrict physical access to the host. Leave the server alone.
- Do NOT use the gateway host as your regular workstation.
Close Window