19.06.2014 Views

Windows Server 2003 Recommended Baseline Security

Windows Server 2003 Recommended Baseline Security

Windows Server 2003 Recommended Baseline Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Unclassified ITSG for <strong>Windows</strong> <strong>Server</strong> <strong>2003</strong><br />

5.3.3 [Service General Setting]<br />

"lanmanserver", 2,<br />

"D:AR(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCDCLCSWRPWPDTLOCR<br />

SDRCWDWO;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"<br />

"browser", 2,<br />

"D:AR(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCDCLCSWRPWPDTLOCR<br />

SDRCWDWO;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"<br />

"spooler", 2,<br />

"D:AR(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCDCLCSWRPWPDTLOCR<br />

SDRCWDWO;;;SY)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)"<br />

5.3.4 Domain Print <strong>Server</strong> IPSec Policy<br />

The following file is supplied as part of the Microsoft <strong>Windows</strong> <strong>Server</strong> <strong>2003</strong> <strong>Security</strong> Guideline.<br />

The file must be modified to reflect domain controller addresses. Once modified the procedure<br />

outlined in 5.1 Role Based IPSec Policies is used to apply the policy.<br />

REM (c) Microsoft Corporation 1997-<strong>2003</strong><br />

REM Packet Filters for <strong>Server</strong> Hardening<br />

REM<br />

REM Name: PacketFilter-File.CMD<br />

REM Version: 1.0<br />

REM This CMD file provides the proper NETSH syntax for creating an IPSec Policy<br />

REM that blocks all network traffic to a File <strong>Server</strong> except for what is<br />

REM explicitly allowed as described in the <strong>Windows</strong> <strong>2003</strong> <strong>Server</strong> Solution Guide.<br />

REM Please read the entire guide before using this CMD file.<br />

REM Revision History<br />

REM 0000 - Original February 05, <strong>2003</strong><br />

REM 0000 - Original April 03, <strong>2003</strong><br />

:IPSec Policy Definition<br />

netsh ipsec static add policy name="Packet Filters - File" description="<strong>Server</strong><br />

Hardening Policy" assign=no<br />

:IPSec Filter List Definitions<br />

netsh ipsec static add filterlist name="CIFS/SMB <strong>Server</strong>" description="<strong>Server</strong><br />

Hardening"<br />

netsh ipsec static add filterlist name="NetBIOS <strong>Server</strong>" description="<strong>Server</strong> Hardening"<br />

122 March 2004 Role Based <strong>Server</strong> Policies

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!