Protect your mssql with Sygate firewall

Joined
Mar 24, 2004
Messages
30
Reaction score
0
I have tested some firewalls on windows and i like Sygate personal firewall pro ( )
To protect your mssql from connect of outside we need to disable outgoing and incoming traffic of mssql.
On Sygate screen find mssql process and with left mouse button select option "Block".




Now we need to set advanced rule for mssql.
Go to Tools > Advanced Rules... > Add
Select "Block this traffic", select "Record this traffic in Packet Log" too, this option let us see mssql trafic on Packet Log section, that way we will see mssql attackers.



On Applications find mssql and select it. This rule will be only for mssql process.



If you dont use mssql servers links then you should to disable it. Go to mssql settings using Enterprise Manager and unselect Sql remotely connect using RPC.

 
Last edited:
Combination of Sygate and NAT Firewall

I use a combination of NAT (on my router) and server firewall (sygate).
If I block the SQL Server Windows NT application, no one can connect to the server.
What is wrong??
How people can play if the sgq server is blocked for in and outgoing traffic??
 
Z80 said:
I use a combination of NAT (on my router) and server firewall (sygate).
If I block the SQL Server Windows NT application, no one can connect to the server.
What is wrong??
How people can play if the sgq server is blocked for in and outgoing traffic??

You can block out/in traffic, but not local, etc localhost aka 127.0.0.1
Check cs and gameserver ports.

Regnarts said:
Please tell me the best way or the best program to block some localport such as 22 (SSH), 23(Telnet), 137, 139, etc...

I suggest Sygate
 
Nemesiz said:
You can block out/in traffic, but not local, etc localhost aka 127.0.0.1
Check cs and gameserver ports.


I don't understand. If I follow your guide, it is blocking the sqlserver.
I tried a different approach:
1) enter in advanced rules
2) Add
3) BlockSql
4) Mark "Block this traffic"
5) open ruler "Applications
6) select SQLServerWindosNT
7) OK
:thumbup:

Now it works fine, everybody can connect and there is silence on incomming and outgoing
.
What do mean with "check" cs and gs ports??
 
i got the same prob.. when i block ports dataserver 1 , 2 and 1433 1431 no one can connect.. so now you say i only block cs port and gs port with TCP and the ports you mentioned that are standard? in other words just block TCP 44405 port TCP 55901 from any traffic?

(i dont want those hackers making their own items and editing their own stuff! :burn: )
 
Last edited:
Make 8 link look like: D:\Muserver\GameServer\GameServer.exe 127.0.0.1 55970 127.0.0.1 55960 55901
Firewall dont block 127.0.0.1 IP becouse its localhost
 
Nemesiz said:
You can block out/in traffic, but not local, etc localhost aka 127.0.0.1
Check cs and gameserver ports.

Wait.. So does this mean you leave CS and GS ports alone since players only need to connect through CS?

And why would it matter if it blocks local or not. People outside localhost cannot connect anyways.

Please Help.
 
nice guide Nemesiz ;)
4 Nemesiz: kaip ten su LMN einas?
 
tai jau greit bus?
laukiam laukiam :)
 
Hm. Instead of blocking the SQL Server, block dataservers 1 and 2.
 
Back