background image

8

Security and Macromedia Breeze

Single Server Configuration

The easiest solution for a dedicated, single-server Breeze system is to block all ports on the Breeze 
box except 80, 1935 (and 443 for SSL-enabled servers). If the Windows server is carefully 
updated by your IT department with the latest Microsoft security patches, a software firewall can 
easily be configured to enable application security. An external hardware firewall appliance can 
provide an extra layer of protection and also provides additional protection against operating 
system flaws. 

Example: Securing a Single Server Configuration

Assume that you are setting up Breeze Live and Breeze Presentation on a single server. In addition, 
the database is also to be installed on this server. You want users to be able to access Breeze on 
the Internet.

Securing Breeze on a single server consists of the following steps:

1

Install a firewall

  Since you are allowing users to access Breeze on the Internet, this means that 

your Breeze server is open to an attack by hackers. By using a firewall, you can block access to 
your servers and control what communications occur between the Internet and your servers.

2

Configure your firewall

  After installing your firewall, you want to configure your firewall 

as follows:

Inbound ports (from the internet): 80, 443, 1935 

Outbound ports (to the mail server): 25 

Since the database is located on the same server as Breeze, you do not need to open up port 
1433 on the firewall.

3

Install Breeze

  For information on installing Breeze, see the Breeze Installation Guide.

4

Verify that Breeze is working

  After installing Breeze, you should verify that Breeze is 

working properly both from the Internet and from your local network. See the Breeze 
Installation Guide for more information.

5

Test your firewall

  Now that you have your firewall installed and configured, you should 

verify that your firewall is working correctly. Test the firewall by attempting to use the 
blocked ports.

Multi-server Solutions 

Multi-server solutions are inherently more complex and will vary from customer to customer. It is 
very important that the customer understand how to secure their multi-server installation. The 
following are suggestions for securing multi-server solutions.

Private Networks

  The simplest solution for multi-server solutions in a single location is to 

create an extra sub-network for the Breeze system. The network is bridged to the customer’s 
network by a firewall device which allows only traffic to the web servers. This offers a high level 
of security but can be expensive. 

Local Software Firewalls

  For Breeze servers located in a cluster but sharing a public 

network with other customer servers, a software firewall may be appropriate on each individual 
server. The simplest route is to allow free communication among the Breeze servers but allow 
outside access only to the web servers. 

VPN Systems

  In multi-server installations where there are multiple Breeze systems in 

different physical locations, customers may want to consider an encrypted channel to the 
remote systems. This setup will probably be uncommon, but many software and hardware 
vendors offer VPN technology to secure the communications to remote Breeze servers. Breeze 
relies on this external security if data traffic must be encrypted.

Summary of Contents for BREEZE-SECURITY

Page 1: ...Security and Macromedia Breeze ...

Page 2: ...ictions including internationally Other product names logos designs titles words or phrases mentioned within this publication may be trademarks servicemarks or tradenames of Macromedia Inc or other entities and may be registered in certain jurisdictions including internationally This guide contains links to third party websites that are not under the control of Macromedia and Macromedia is not res...

Page 3: ... Overview 5 Security Levels 6 Infrastructure Security 6 Solutions for a Secure Infrastructure 7 Application Level Security 9 Physical Security 9 Best Practices 10 Recommended Security Resources and References 11 ...

Page 4: ...4 Contents ...

Page 5: ...anywhere anytime By its very nature any application that is run over a network especially the Internet has security risks associated with it Macromedia Breeze is no different However these security threats can be minimized if careful consideration is taken towards implementing a security design for Macromedia Breeze There are three levels of security that should be considered for Macromedia Breeze...

Page 6: ...channels for private communication These ports must be protected from outside users Breeze s design requires the environment to provide security for these communications It is highly recommended that sensitive ports should be placed behind a firewall that separates them from non trusted machines Below is a list of ports that are used by Macromedia Inbound ports from the internet 80 443 1935 Outbou...

Page 7: ...cure location Databases should be installed in the secure zone of your corporate intranet and never directly connected to the Internet Back up all data regularly and store copies in a secure off site location The Microsoft security web site contains information that applies to both securing SQL Server 2000 and the Breeze built in database www microsoft com sql techinfo administration 2000 security...

Page 8: ...tion Guide 4 Verify that Breeze is working After installing Breeze you should verify that Breeze is working properly both from the Internet and from your local network See the Breeze Installation Guide for more information 5 Test your firewall Now that you have your firewall installed and configured you should verify that your firewall is working correctly Test the firewall by attempting to use th...

Page 9: ...enrollee notifications and setting up course reminders They can also view content and course reports Meeting Administrators Members of the Meeting Administrators are able to perform all functions associated with creating meetings including setting up a meeting inviting participants sending invitations and viewing reports In addition to adding users to groups to grant them rights to use features in...

Page 10: ...atched with all security updates approved by Microsoft or other appropriate platform vendor Perform Database Security Updates Since your database may be another targeted component of the Breeze solution you need to check for database server security holes and apply required patches Like the operating system some of these issues are eliminated by a good firewall but you should also keep up to date ...

Page 11: ... information on this site also applies to the Breeze built in database engine Tools Freeware NMap www insecure org nmap index html A powerful port scanning program that tells you what ports a system is listening on It is freely available under the GNU Public License GPL Note Please note that the effectiveness of any security measure is determined by various factors including but not limited to the...

Page 12: ...12 Security and Macromedia Breeze ...

Reviews: