all groups > iis security > september 2007 >
You're in the

iis security

group:

Microsoft Update


Microsoft Update George Schneider
9/30/2007 8:42:00 PM
iis security: Currently we have our web server compleley locked down by only allowing the
web server to get out to needed websites by adding a rule to the
router/firewall acl. I can't seem to find a way to allow access to microsoft
updtae which would need to be allowed by IP address. Can someone tell me the
ip addresses or range i can specify on my router to allow this for the web
Re: Microsoft Update Ken Schaefer
10/2/2007 12:00:00 AM
Does your router support DNS names as ACLs? or only IP addresses?

Alternatively, have you looked at hosting a WSUS server internally - that
way your client machines (e.g. your IIS server) would just get their updates
from a local server.

Cheers
Ken

[quoted text, click to view]
Re: Microsoft Update Roger Abell [MVP]
10/2/2007 5:36:09 PM
When Windows Update was first starting out I raised this same
item with Microsoft for the very same reason. Bottom line is that
to date there is no listing of IPs (to my awareness) and there is not
likely to be one (two main reasons: security - don't advertise what
you do not want DoS deluged; and, the IPs change and are also
dependent on where in the world one is as there are multiple
feeds and these are outsourced to well-connected providers).
On servers that need to visit Microsoft Update I have a normally
not enabled rule that allows outbound tcp 80 and 443, and if there
is not already one that allows inbound on the same ports. This
rule is enabled for the 10 minutes less or more that is needed,
and then returned to its normal, not enabled state.

Roger

[quoted text, click to view]

Re: Microsoft Update George Schneider
10/4/2007 4:45:00 PM
Thats the long term solution to setup a wsus internally and the problem
ceases to exist. In the immediate future is i've had to create an acl to
allow 80 and 443 in and out on established connections when I'm ready to
update.

As far as I know the ACL's on cisco routers/firewalls only support IP.

[quoted text, click to view]
Re: Microsoft Update George Schneider
10/4/2007 4:47:01 PM
I've done a similar thing as well creating an acl that to allow this then
remove it when i'm done. I understand Microsoft's reasoning but it makes it
real hard for security if er completly lock something down and only specifc
access. I guess this is there way of forcing the issue with wsus.

[quoted text, click to view]
Re: Microsoft Update Roger Abell [MVP]
10/4/2007 6:44:11 PM
I actually think it is such that MS would just as soon it could be
otherwise, but again, management of what is outsourced is not
something they can constrain and still get the volume/scale.

Roger

[quoted text, click to view]

AddThis Social Bookmark Button