Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations bkrike on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

How can I block port 1433?

Status
Not open for further replies.

jmille34

Programmer
Sep 14, 2005
224
US
I have an internet server running sql server, and I need to block port 1433 from non-localhost connections so we can pass a security audit. I tried using sql server's built-in functionality by checking a box called "hide server" in the network properties, but that cause connectivity problems even for localhost. So I think what I need to do is block it on an IP level somehow. Unfortunately, I cannot touch the firewall, or else I would try that first. Can I do it using built-in windows functionality? I do not have the windows firewall turned on, and I am hesitant to do so, because I have to configure the machine remotely. I do not want to saw the limb out from under my own butt, if you know what I mean. There is also config page on the tcp/ip properties for the network connection that will allow either "accept all" or "accept only" but not "accept all except" which would be the one I need.

So I'm not sure what to do about it.. any suggestions?
 
If you would like, you can setup windows firewall and make sure the exception for RDP is setup so that you dont end up shooting yourself in the foot. Its pretty straight forward and I think this might be a good quickfix for you.
 
Oh I would say test this process out on a noncritical machine (like a laptop you have sitting next to you with XP Pro or something) before going through with it though so you know you got it all figured out beforehand;)
 
I am sure you already know the answer to this. The best way to handle this is one of two ways or both ways. Move the SQL server to a non-internet facing server and or get whom ever admins the firewall to block the port. Obviously the firewall fix would be easist for you but good network setup and protocal says dont install SQL servers on internet facing servers.

Just my 2 cents,

RoadKi11
 
Thanks Roadkill thats way better advice, but since he mentioned he didnt have access to setting up his companies firewall I assumed he was under the gun for a quick fix.

Although you may fail the initial audit at first, bringing this type of information up to whomever is in charge of the overall setup is very valuable and should be received in high regard from the higher ups.

Good luck in any event.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top