Protect your mssql with Sygate firewall

Page 1 of 2 12 LastLast
Results 1 to 25 of 33
  1. #1
    Account Upgraded | Title Enabled! Nemesiz is offline
    MemberRank
    Mar 2004 Join Date
    LithuaniaLocation
    204Posts

    Protect your mssql with Sygate firewall

    I have tested some firewalls on windows and i like Sygate personal firewall pro (http://smb.sygate.com/products/spf_pro.htm)
    To protect your mssql from connect of outside we need to disable outgoing and incoming traffic of mssql.
    On Sygate screen find mssql process and with left mouse button select option "Block".




    Now we need to set advanced rule for mssql.
    Go to Tools > Advanced Rules... > Add
    Select "Block this traffic", select "Record this traffic in Packet Log" too, this option let us see mssql trafic on Packet Log section, that way we will see mssql attackers.



    On Applications find mssql and select it. This rule will be only for mssql process.



    If you dont use mssql servers links then you should to disable it. Go to mssql settings using Enterprise Manager and unselect Sql remotely connect using RPC.

    Last edited by Nemesiz; 13-08-09 at 06:05 PM. Reason: img moved to another location


  2. #2
    Account Upgraded | Title Enabled! Nemesiz is offline
    MemberRank
    Mar 2004 Join Date
    LithuaniaLocation
    204Posts
    Or you can just block UDP 1431 and 1433 ports

  3. #3
    Alpha Member Hybr!d is offline
    MemberRank
    Sep 2004 Join Date
    Sydney NSW AustLocation
    2,960Posts
    Nice work man good guide to.

  4. #4
    Valued Member Z80 is offline
    MemberRank
    Jul 2004 Join Date
    Belo Horizonte, BrazilLocation
    120Posts

    Combination of Sygate and NAT Firewall

    I use a combination of NAT (on my router) and server firewall (sygate).
    If I block the SQL Server Windows NT application, no one can connect to the server.
    What is wrong??
    How people can play if the sgq server is blocked for in and outgoing traffic??

  5. #5
    Enthusiast Regnarts is offline
    MemberRank
    Nov 2004 Join Date
    now ? In RageZone!Location
    38Posts
    Please tell me the best way or the best program to block some localport such as 22 (SSH), 23(Telnet), 137, 139, etc...

  6. #6
    Account Upgraded | Title Enabled! Nemesiz is offline
    MemberRank
    Mar 2004 Join Date
    LithuaniaLocation
    204Posts
    Quote Originally Posted by Z80
    I use a combination of NAT (on my router) and server firewall (sygate).
    If I block the SQL Server Windows NT application, no one can connect to the server.
    What is wrong??
    How people can play if the sgq server is blocked for in and outgoing traffic??
    You can block out/in traffic, but not local, etc localhost aka 127.0.0.1
    Check cs and gameserver ports.

    Quote Originally Posted by Regnarts
    Please tell me the best way or the best program to block some localport such as 22 (SSH), 23(Telnet), 137, 139, etc...
    I suggest Sygate

  7. #7
    Valued Member Z80 is offline
    MemberRank
    Jul 2004 Join Date
    Belo Horizonte, BrazilLocation
    120Posts
    [QUOTE=Nemesiz]You can block out/in traffic, but not local, etc localhost aka 127.0.0.1
    Check cs and gameserver ports.


    I don't understand. If I follow your guide, it is blocking the sqlserver.
    I tried a different approach:
    1) enter in advanced rules
    2) Add
    3) BlockSql
    4) Mark "Block this traffic"
    5) open ruler "Applications
    6) select SQLServerWindosNT
    7) OK


    Now it works fine, everybody can connect and there is silence on incomming and outgoing
    .
    What do mean with "check" cs and gs ports??

  8. #8
    Account Upgraded | Title Enabled! Nemesiz is offline
    MemberRank
    Mar 2004 Join Date
    LithuaniaLocation
    204Posts
    For players need only CS.exe TCP 44405 port and GAMESERVER.exe TCP 55901 (standard) port.

  9. #9
    Member blindscout is offline
    MemberRank
    Jun 2004 Join Date
    TOXICITY!Location
    72Posts
    i got the same prob.. when i block ports dataserver 1 , 2 and 1433 1431 no one can connect.. so now you say i only block cs port and gs port with TCP and the ports you mentioned that are standard? in other words just block TCP 44405 port TCP 55901 from any traffic?

    (i dont want those hackers making their own items and editing their own stuff! :burn: )
    Last edited by blindscout; 05-02-05 at 07:34 AM.

  10. #10
    Account Upgraded | Title Enabled! Nemesiz is offline
    MemberRank
    Mar 2004 Join Date
    LithuaniaLocation
    204Posts
    Make 8 link look like: D:\Muserver\GameServer\GameServer.exe 127.0.0.1 55970 127.0.0.1 55960 55901
    Firewall dont block 127.0.0.1 IP becouse its localhost

  11. #11
    Valued Member holm is offline
    MemberRank
    Jul 2004 Join Date
    MidgardLocation
    109Posts

    any other idea for full protection?

    Anyone knows how to protect your CS from port attacks?

    Read here -> http://forum.ragezone.com/showthread.php?t=59808

    This will be the last problem you'll ever bother, when users knows how to distract your
    server's connections.

  12. #12
    Apprentice noobnr1 is offline
    MemberRank
    Jun 2005 Join Date
    8Posts
    thx alot

  13. #13
    S+kite = Me =D Skite is offline
    MemberRank
    Aug 2004 Join Date
    301Posts
    Quote Originally Posted by Nemesiz
    You can block out/in traffic, but not local, etc localhost aka 127.0.0.1
    Check cs and gameserver ports.
    Wait.. So does this mean you leave CS and GS ports alone since players only need to connect through CS?

    And why would it matter if it blocks local or not. People outside localhost cannot connect anyways.

    Please Help.

  14. #14
    Account Upgraded | Title Enabled! Nemesiz is offline
    MemberRank
    Mar 2004 Join Date
    LithuaniaLocation
    204Posts
    Skite for players need only cs ang gameserver ports.

  15. #15
    Valued Member BHD is offline
    MemberRank
    Jun 2004 Join Date
    Lithuania;SiauliaiLocation
    101Posts
    nice guide Nemesiz ;)
    4 Nemesiz: kaip ten su LMN einas?

  16. #16
    Account Upgraded | Title Enabled! Nemesiz is offline
    MemberRank
    Mar 2004 Join Date
    LithuaniaLocation
    204Posts
    Puse velnio, neturiu baisiai laiko bet jau resetus testinu.

  17. #17
    Valued Member BHD is offline
    MemberRank
    Jun 2004 Join Date
    Lithuania;SiauliaiLocation
    101Posts
    tai jau greit bus?
    laukiam laukiam :)

  18. #18
    S+kite = Me =D Skite is offline
    MemberRank
    Aug 2004 Join Date
    301Posts
    Hm. Instead of blocking the SQL Server, block dataservers 1 and 2.

  19. #19
    Little kid davevleugel is offline
    MemberRank
    Apr 2004 Join Date
    netherlandsLocation
    398Posts
    When i instal sygates i dont have internet ore even network anymore....My messenger don't work then.

    can sombody explain me why??

    i got a router

  20. #20
    Account Upgraded | Title Enabled! Nemesiz is offline
    MemberRank
    Mar 2004 Join Date
    LithuaniaLocation
    204Posts

  21. #21
    Little kid davevleugel is offline
    MemberRank
    Apr 2004 Join Date
    netherlandsLocation
    398Posts
    Ok i try (thanx for help)

  22. #22
    Member codrin is offline
    MemberRank
    Aug 2005 Join Date
    MainFrameLocation
    96Posts
    dude .... nice guide ..... :) only 1 problem though ..... i did exactly as said in the guide .... but now no one can lvl up. when they switch their caracter it resets their caracter to the moment i installed the firewall. main problem : server at a standstill. :( please help.:eh:

  23. #23
    meet duckie... darranthegreat is offline
    MemberRank
    Aug 2005 Join Date
    SingaporeLocation
    1,410Posts
    i did everything and my server works fine. but my players cant access my website..o.O

  24. #24
    Account Upgraded | Title Enabled! Dark_FearZz is offline
    MemberRank
    Aug 2005 Join Date
    Black RoadLocation
    265Posts
    I connect to my server only by remote.what i must add to sygate so as not to block me?!?I tried it many times but always blocked me!!!Help

  25. #25
    Account Upgraded | Title Enabled! Dark_FearZz is offline
    MemberRank
    Aug 2005 Join Date
    Black RoadLocation
    265Posts
    I connect to my server only by remote.Even i tried to install the Sygate Firewall always blocks access by remote!!!Help me ...



Page 1 of 2 12 LastLast

Advertisement