background image

6

Security and Macromedia Breeze

Security Levels

When planning a security strategy, it is important to consider the various layers of a deployed 
server environment, and devise a plan for each layer. Typically, a comprehensive security strategy 
incorporates the following elements:

Infrastructure Security

Application-Level Security

Physical Security

Infrastructure Security

Infrastructure security is by far the most important, but most overlooked, aspect of securing 
Breeze. It is up to your IT team to provide a secure infrastructure for Breeze.

There are three parts to providing a secure infrastructure for Breeze:

Network Security

Breeze Web Server Security

Database Server Security

The following sections describe a secure infrastructure. The security measures you implement 
depend on whether your Breeze system consists of just a single server running in the DMZ or an 
elaborate multi-server system running with different trusted zones. 

Network Security

Breeze relies on several private TCP/IP services for its communications model. These services 
open several ports and channels for private communication. These ports must be protected 
from outside users. Breeze’s design requires the environment to provide security for these 
communications. It is highly recommended that sensitive ports should be placed behind a 
firewall that separates them from non-trusted machines. 

Below is a list of ports that are used by Macromedia: 

Inbound ports (from the internet): 80, 443, 1935 

Outbound ports (to the database): 1433 

Outbound ports (to the mail server): 25 

Local ports (to/from other members in the cluster): 8505, 8510, 8520

If you intend to have users access Breeze on your intranet, it is recommended that you place your 
Breeze servers and your Breeze database in a separate sub-network, separated by a firewall. This 
configuration of the firewall should take into consideration the above ports and whether they 
should be set as inbound or outbound. 

However, if you intend to have users access Breeze on the Internet, it is extremely important that 
you separate your Breeze servers from the Internet with a firewall. If you do not take the necessary 
steps to secure your Breeze servers, you are leaving your valuable information available for anyone 
to steal. For references to resources on network security, see 

“Recommended Security Resources 

and References” on page 11

.

Summary of Contents for BREEZE-SECURITY

Page 1: ...Security and Macromedia Breeze ...

Page 2: ...ictions including internationally Other product names logos designs titles words or phrases mentioned within this publication may be trademarks servicemarks or tradenames of Macromedia Inc or other entities and may be registered in certain jurisdictions including internationally This guide contains links to third party websites that are not under the control of Macromedia and Macromedia is not res...

Page 3: ... Overview 5 Security Levels 6 Infrastructure Security 6 Solutions for a Secure Infrastructure 7 Application Level Security 9 Physical Security 9 Best Practices 10 Recommended Security Resources and References 11 ...

Page 4: ...4 Contents ...

Page 5: ...anywhere anytime By its very nature any application that is run over a network especially the Internet has security risks associated with it Macromedia Breeze is no different However these security threats can be minimized if careful consideration is taken towards implementing a security design for Macromedia Breeze There are three levels of security that should be considered for Macromedia Breeze...

Page 6: ...channels for private communication These ports must be protected from outside users Breeze s design requires the environment to provide security for these communications It is highly recommended that sensitive ports should be placed behind a firewall that separates them from non trusted machines Below is a list of ports that are used by Macromedia Inbound ports from the internet 80 443 1935 Outbou...

Page 7: ...cure location Databases should be installed in the secure zone of your corporate intranet and never directly connected to the Internet Back up all data regularly and store copies in a secure off site location The Microsoft security web site contains information that applies to both securing SQL Server 2000 and the Breeze built in database www microsoft com sql techinfo administration 2000 security...

Page 8: ...tion Guide 4 Verify that Breeze is working After installing Breeze you should verify that Breeze is working properly both from the Internet and from your local network See the Breeze Installation Guide for more information 5 Test your firewall Now that you have your firewall installed and configured you should verify that your firewall is working correctly Test the firewall by attempting to use th...

Page 9: ...enrollee notifications and setting up course reminders They can also view content and course reports Meeting Administrators Members of the Meeting Administrators are able to perform all functions associated with creating meetings including setting up a meeting inviting participants sending invitations and viewing reports In addition to adding users to groups to grant them rights to use features in...

Page 10: ...atched with all security updates approved by Microsoft or other appropriate platform vendor Perform Database Security Updates Since your database may be another targeted component of the Breeze solution you need to check for database server security holes and apply required patches Like the operating system some of these issues are eliminated by a good firewall but you should also keep up to date ...

Page 11: ... information on this site also applies to the Breeze built in database engine Tools Freeware NMap www insecure org nmap index html A powerful port scanning program that tells you what ports a system is listening on It is freely available under the GNU Public License GPL Note Please note that the effectiveness of any security measure is determined by various factors including but not limited to the...

Page 12: ...12 Security and Macromedia Breeze ...

Reviews: