Article ID: 255784 - Last Review: March 1, 2007 - Revision: 2.2 Increasing Security on Windows 2000 VPN ServerThis article was previously published under Q255784 SUMMARY
A Windows 2000 virtual private network (VPN) server that is configured by using the Routing and Remote Access Services (RRAS) Setup Wizard is installed with a default set of Input and Output filters. These filters support Point-to-Point Tunneling Protocol (PPTP), Layer 2 Tunneling Protocol (L2TP), and IP Security Protocol (IPSec) connectivity. The filters are generic and can be modified to tighten security on a VPN server. This article describes modifications that you can make to these filters to increase security. All filter configurations mentioned in this article should be tested prior to being deployed in a production environment.
MORE INFORMATION
The RRAS Setup Wizard creates a set of default Input and Output Filters on the external adapter on the VPN server. To display and edit these filters:
Collapse this table
Greater security can be provided by editing each of these filters (with the exception of the PROTOCOL 47 GRE filter) and further restricting the flow of PPTP and/or L2TP/IPSec packets. You must edit the Input and Output filters. The result is that inbound PPTP, L2TP/IPSec traffic will be restricted to the IP address of the external adapter and only PPTP, L2TP/IPSec traffic will be allowed to pass out through the external adapter from the internal network or the VPN server itself. Input and Output filters are edited individually by selecting the filter and then clicking Edit button. The Edit IP Filter dialog box allows you to modify each filter setting. As an example, assume that the external adapter has an IP address of 192.0.0.40 with a subnet mask of 255.255.255.0. After modifying the Input filters, the displayed matrix would look like: Collapse this table
After modifying the Output filters, the displayed matrix would look like: Collapse this table
These filter settings also accommodate a VPN server that can support a requirement for initiating a demand-dial connection to another VPN server, for example. The default filter settings that installed by using the RRAS Setup Wizard allow for VPN connections only. The information in this article is provided for those who want increased security.
| Article Translations
|
Back to the top
