Microsoft SharePoint Products and Technologies Administrators Pocket Consultant

The key to a secure SharePoint installation is limiting the number of nonessential services on your servers. Be thoughtful in your server farm design and limit the external exposure of critical services, such as SQL Server connections. In addition, Windows Updates are imperative to hardening the Windows Server operating system.

Surface Area

If your server farm is Internet-facing, use caution when configuring the Windows Server system. When possible, restrict access to nonessential ports using firewalls or the Windows Server native IP Security Policies MMC snap-in. This book obviously cannot provide a comprehensive list of ports, but the following ports should be the minimum set that have restricted access:

Figure 7-11: The TCP port number used by Central Administration appears after the "-" in the URL.

Server Placement

You can isolate and effectively protect your server farm by exclusively using Windows Server IP Security Policies, but this practice does not scale well. Using IP Security Policies in a large environment can introduce complexities with inter-server processes and client-server processes. For this reason, most medium-scale and larger implementations protect the majority of their server surface area with firewalls, routers, and proxy servers. The following is an example of securing a medium-scale server farm.

Figure 7-12: Isolate the Web front ends and SQL Server traffic to reduce the external surface area available to hackers.

Категории