Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Microsoft XP SP2 blocks SQL Server 1

Status
Not open for further replies.

SQLBill

MIS
May 29, 2001
7,777
US
Microsoft has issued XP Service Pack 2. It is affecting 50 known products and one of them is SQL Server.

The issue is that the service pack turns on the built-in firewall. This firewall is capable of blocking incoming and/or outgoing traffic by ports.

Can you guess what two of the blocked ports are? Did you guess 1433 and 1434? Yep. Microsoft blocks the default ports used for their own product.

Check the following link (MS Knowledgebase Article) for more information.


-SQLBill
 
Okay.....it's not a question, but I clicked on the Helpful Tip before posting and it used the question mark instead.

-SQLBill
 
That's just beautiful. Although I supose Microsoft taking a hard stand about security is a good think though.

Denny

--Anything is possible. All it takes is a little research. (Me)
 
I don't know what basis they used to block all the ports they do, but I'm guessing that they are blocking 1433 and 1434 because of things like Slammer. Maybe the other products/ports being blocked are also ones likely/known to be hit by virus'/worms.

-SQLBill
 
Most likely, instead of blocking individual ports, they blocked ALL ports except for the ones necessary for basic pc operations (web, email, ect...). So, instead of closing what you don't want, you now have to open what you do want. I guess that since the majority of users probably don't need those ports, it's now up to us to set up a pc to allow them...



Hope This Helps!

Ecobb

"My work is a game, a very serious game." - M.C. Escher
 
Ecobb is probally correct. From what I know of secure filre walls you start with a deny-all, then start opening ports (microsoft has always done this the other way). I remember reading somewhere, that to help network admins roll out SP2, you can download the whole thing, and configure what it locks down, then push that out via SUS and your life "should" be easier.

Denny

--Anything is possible. All it takes is a little research. (Me)
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top