Protecting a RAS Server from Internet Attacks

If PPTP filtering is selected, the selected network adapter for all other protocols is effectively disabled. Only PPTP packets will be allowed in.

Terra Flora will want to do this on all multihomed computers with one network adapter (with PPTP filtering enabled) connected to the Internet and another network adapter connected to the internal corporate network. Clients outside the corporate network can use PPTP to connect to the computer from across the Internet and gain secure access to the corporate network. Thus, the only traffic that can access the corporate network is PPTP packets from clients who have been authenticated using RAS authentication.

Note

The RAS client can either be connected to the Internet directly or to a service provider. It is not necessary to be connected to both to use PPTP.

To install PPTP filtering for protection

1. Click Start, point to Settings, and click Control Panel.

2. Double-click Network.

3. Click the Protocols tab.

4. Click TCP/IP Protocol.

5. Click Properties.

6. Click the IP Address tab, if necessary, and then click Advanced.

7. In Adapter, click the network adapter for which you want to specify PPTP filtering.

The PPTP filtering settings in this dialog box are defined only for the selected network adapter.

8. To enable PPTP filtering, click Enable PPTP Filtering.

You must restart the computer to have the settings take effect.

For more information about advanced TCP/IP configuration, see the topic "To Configure Advanced TCP/IP Options" in the TCP/IP online Help file.