电脑知识|欧美黑人一区二区三区|软件|欧美黑人一级爽快片淫片高清|系统|欧美黑人狂野猛交老妇|数据库|服务器|编程开发|网络运营|知识问答|技术教程文章 - 好吧啦网

您的位置:首頁技術文章
文章詳情頁

Don’t Let the Defense Rest: Securing Home Networks with Windows XP

瀏覽:13日期:2023-07-20 17:45:51

It's sad, but true—there are some not so nice people out there, and that includes Internet abusers who want to wreak havoc on your computer and make your life miserable. While just about everyone on the planet has a good anti–virus program installed these days, this type of protection may not be enough. So, what should your first line of defense be? A firewall can stop invaders from gaining access to your computer. In essence, a firewall provides protection from port scanning and disables access to shared folders, files, and printers, which keeps the bad guys from copying files and programs to your computer that can cause serious problems when executed.

A good rule of thumb is that any computer connected directly to the Internet should also be protected by a firewall. A personal firewall can be your ticket to strong intruder protection and peace of mind.

A good rule of thumb is that any computer connected directly to the Internet should also be protected by a firewall. A personal firewall can be your ticket to strong intruder protection and peace of mind.

And now for the good news! If you are running Microsoft Windows XP Professional or Home Edition, Windows XP Media Center Edition, or Windows XP Tablet PC Edition, you've already got access to a built–in basic firewall. Microsoft Internet Connection Firewall (ICF) is included as a Windows XP networking feature and you should enable it if you need firewall protection. (If you've set up your Internet connection using the wizard and selected a direct or dial–up connection to the Internet, ICF may already be enabled.)

When running Windows XP, ICF opens and closes most ports on the firewall dynamically as you access services but there are a few exceptions. (See the Windows Messenger and ICF section below for details on manually configuring ports to enable file transfer and voice calls). Since Internet Connection Firewall provides inbound protection only, if you have concerns about programs that “phone home” or send outbound data to an unknown destination over the Internet, you may want to consider a third–party firewall.

Who Needs Firewall Protection?

You need protection if you have a direct, dial–up connection to the Internet, a single computer connected to a cable modem, or a single computer connected to a DSL modem. You'll also want to enable a firewall on the Windows XP–based host computer (and only the host computer) that is used for Internet Connection Sharing (ICS). If you're a broadband user with two or more ISP assigned IPs connected through a hub, you'll need to protect each computer individually. An easy rule of thumb—if a computer connects directly to the Internet, it needs protection.

To activate ICF:

1.

Click Start , and then click My Network Places .

2.

Under Network Tasks , click VIEw Network Connections . (Alternatively, you can right–click My Network Places and then click Properties .)

3.

Right–click the connection used for the Internet, and then click Properties .

4.

Click the Advanced tab, and select the Protect my computer and network check box to turn on ICF. (This also makes the Settings button active, allowing you to configure advanced parameters.)

Top of page Windows Messenger and ICF

Most of the time, my computers are connected wirelessly through one of my Network Address Translation (NAT) boxes that is connected to an AT&T Broadband cable modem. I'm waiting for UPnP firmware for these units that will enable Nat traversal so I can use all of the features of programs like Windows Messenger behind them. (Voice and video instant messaging were not working behind these NAT boxes when I wrote this column, but I'm hoping for firmware that will make this possible and when it arrives, I'll share information on the new UPnP NAT capabilities here in the Expert Zone.) When I wish to use the voice and video instant messaging real time communications (RTC) features, I connect a computer directly to my cable modem, and I enable the Internet Connection Firewall for these sessions.

Windows Messenger version 4.0, which ships with Windows XP, as well as the updated Windows Messenger 4.7 that is now available, also include the ability to transfer files. However, by default, ICF blocks file transfer and you will need to manually configure the appropriate ports to open. Here's how it's accomplished:

1.

Click Settings on the Advanced tab of the Properties dialog box for your Internet connection, then click Add .

2.

In the Service Settings window, type a description of the service.

3.

Type the IP address or the computer name.

4.

For Windows Messenger file transfer capabilities, the External and Internal Ports are the same and both are TCP. Use 6891 for both. If you wish to enable simultaneous transfer of up to 10 files, after clicking OK, set up additional ports in the same manner, numbering sequentially through 6900. You'll need 10 service entries total.

Additionally, you will have open Port 6901 for both TCP and UDP to receive incoming computer to computer voice calls and UDP Ports 6801, 6901, 2001–2120 for computer to phone voice calls.

As shown in the image above, I've enabled a single port only for a single file transfer only. The process to open ports to add other services is the same. Settings needed for some of the other more popular programs appear in the table below:

Program TCP ports UDP ports

Incoming Voice (computer to computer)

6901

6901

Voice (computer to phone)

6801, 6901, 2001–2120

AOL Instant Messenger

443, 563

Crimson Skies

28805, 28801, 3040, 1121

Decent 3

1900

1900, 2092

Diablo II

4000

6112

Need for Speed

9442

6112

Napster

6699

6699

NetMeeting

1731, 1720, 1503, 522, 389

Rainbow Six

2346, 2347, 2348

Top of page Security Logging and Trouble Shooting

If you want to examine incoming connection attempts, you can turn on logging from the ICF Advanced Settings tab as well as specify the size of a log file. If you're experiencing connectivity issues and need to trouble shoot your connection, the ICMP tab provides some configuration options for this purpose.

Top of page Some Special Circumstances

VPN Usage : If you're a VPN user and connect to a remote Office, you should not use ICF. Turn it off before you start your VPN session.

File and Print Sharing : Some broadband providers offer connectivity for more than a single computer and supply multiple public routable IPs. In this case, computers are connected to a hub or switch (rather than a router or NAT box) that connects to a cable or DSL modem. Since ICF disables file and print sharing using TCP/IP, you may need an alternative method of sharing files among your own computers. You can install an additional network transport protocol such as IPX/SPX that will enable you to transfer files between your computers. To install IPX/SPX, from the Connection Properties dialog box, select Install , then select Protocol , Add and then NWLink IPX/SPX/NetBIOS Compatible Transport Protocol .

Outgoing Windows Messenger Calls Behind ICF: If you are using Windows XP Professional, ensure you are using an account with administrative privileges; otherwise outbound calls will not work. (Users of Windows XP Home Edition are assigned the proper administrative privileges by default.)

Top of page Who Does Not Need to Enable Internet Connection Firewall?

If a computer is a client computer to an ICS (Internet Connection Sharing) host, do not enable ICF, but be sure you do enable it on the host computer. If a computer is behind a NAT box or router, don't enable ICF, because the inherent properties of NAT will protect you. If you're in an enterprise/corporate environment, don't enable ICF while logged into a domain at work because your IT staff will have proper commercial firewalls in place on the network. In most cases, user policies will prevent you from enabling ICF if you are logged into a domain. If you've logged on at home using cached credentials and enabled ICF, user policies will probably prevent you from using ICF at work, but you will be able to use it at home while not protected by the corporate firewall.

Barb Bowman enjoys sharing her own experiences and insights into today's leading edge technologies. She is a product development manager for AT&T Broadband Internet Services, but her views here are strictly personal.

標簽: Windows系統
主站蜘蛛池模板: 展厅设计-展馆设计-专业企业展厅展馆设计公司-昆明华文创意 | 搜木网 - 木业全产业链交易平台,免费搜货、低价买货! | 浙江红酒库-冰雕库-气调库-茶叶库安装-医药疫苗冷库-食品物流恒温恒湿车间-杭州领顺实业有限公司 | 热熔胶网膜|pes热熔网膜价格|eva热熔胶膜|热熔胶膜|tpu热熔胶膜厂家-苏州惠洋胶粘制品有限公司 | 轻型地埋电缆故障测试仪,频响法绕组变形测试仪,静荷式卧式拉力试验机-扬州苏电 | 涿州网站建设_网站设计_网站制作_做网站_固安良言多米网络公司 | 手术室净化装修-手术室净化工程公司-华锐手术室净化厂家 | 申江储气罐厂家,储气罐批发价格,储气罐规格-上海申江压力容器有限公司(厂) | 高压微雾加湿器_工业加湿器_温室喷雾-昌润空气净化设备 | 体坛网_体坛+_体坛周报新闻客户端| 预制围墙_工程预制围墙_天津市瑞通建筑材料有限公司 | 锯边机,自动锯边机,双面涂胶机-建业顺达机械有限公司 | 环球电气之家-中国专业电气电子产品行业服务网站! | 学叉车培训|叉车证报名|叉车查询|叉车证怎么考-工程机械培训网 | 北京银联移动POS机办理_收银POS机_智能pos机_刷卡机_收银系统_个人POS机-谷骐科技【官网】 | 进口消泡剂-道康宁消泡剂-陶氏消泡剂-大洋消泡剂 | 环氧树脂地坪漆_济宁市新天地漆业有限公司 | 球形钽粉_球形钨粉_纳米粉末_难熔金属粉末-广东银纳官网 | 灌装封尾机_胶水灌装机_软管灌装封尾机_无锡和博自动化机械制造有限公司 | 小型数控车床-数控车床厂家-双头数控车床 | 众品家具网-家具品牌招商_家具代理加盟_家具门户的首选网络媒体。 | 首页|光催化反应器_平行反应仪_光化学反应仪-北京普林塞斯科技有限公司 | 恒温恒湿箱(药品/保健品/食品/半导体/细菌)-兰贝石(北京)科技有限公司 | 生物制药洁净车间-GMP车间净化工程-食品净化厂房-杭州波涛净化设备工程有限公司 | 传动滚筒,改向滚筒-淄博建凯机械科技有限公司| 拉曼光谱仪_便携式|激光|显微共焦拉曼光谱仪-北京卓立汉光仪器有限公司 | 磁力加热搅拌器-多工位|大功率|数显恒温磁力搅拌器-司乐仪器官网 | 合肥宠物店装修_合肥宠物美容院装修_合肥宠物医院设计装修公司-安徽盛世和居装饰 | 天津散热器_天津暖气片_天津安尼威尔散热器制造有限公司 | 彭世修脚_修脚加盟_彭世修脚加盟_彭世足疗加盟_足疗加盟连锁_彭世修脚技术培训_彭世足疗 | 层流手术室净化装修-检验科ICU改造施工-华锐净化工程-特殊科室建设厂家 | 禹城彩钢厂_钢结构板房_彩钢复合板-禹城泰瑞彩钢复合板加工厂 | 丹佛斯变频器-丹佛斯压力开关-变送器-广州市风华机电设备有限公司 | 广东成考网-广东成人高考网| 钢衬四氟管道_钢衬四氟直管_聚四氟乙烯衬里管件_聚四氟乙烯衬里管道-沧州汇霖管道科技有限公司 | 金现代信息产业股份有限公司--数字化解决方案供应商 | 生态板-实木生态板-生态板厂家-源木原作生态板品牌-深圳市方舟木业有限公司 | 上海宿田自动化设备有限公司-双面/平面/单面贴标机 | 真空泵维修保养,普发,阿尔卡特,荏原,卡西亚玛,莱宝,爱德华干式螺杆真空泵维修-东莞比其尔真空机电设备有限公司 | 生物制药洁净车间-GMP车间净化工程-食品净化厂房-杭州波涛净化设备工程有限公司 | 深圳市简易检测技术有限公司|