|
|
| |
Configuring PatchLink
Update for IIS Lockdown Tool 2.1 |
|
- Download the IIS
Lockdown Tool from the Microsoft’s Website:
http://www.microsoft.com/downloads/details.aspx?displaylang=en&FamilyID=DDE9EFC0-BB30-47EB-9A61-FD755D23CDEC

- Remember: The
PatchLink Update Server should be installed first. Create an
IISLock directory and use WinZip or
another zip extracting utility to extract the files within the IIS
Lockdown Tool.

- Once the files are
extracted, open the urlscan dynamic.ini
in notepad and allow the following http request: PUT, POST, HEAD,
GET.

- Look for the [Deny
Executables that could run the Server], please allow .exe so you
can download the Update Agent Installers.

- Look for [AllowExtensions] and insert .aspx so the graphs will display in version
5.0

- Once the “INI” file
has been updated and saved, launch the iislockd.exe to launch the
“Lockdown Wizard”.

- Accept the license
agreement, click “Next”.

- Select Server
Template: Choose the template for “Dynamic Web Server” (ASP
enabled).

- Internet Services:
Ensure Web Service (HTTP) is selected and click next.

- Script Maps: Verify
that you do not disable script maps for “Active Server Pages”
(asp).

- Additional Security:
Choose the default virtual directories you wish to disable.

- URLScan: When you place a
check mark in the “Install URLScan
Filter on the Server” box, this will load the
urlscan_dynamic.ini.

- Ready to Apply
Settings: Click the “Next” Button to apply the settings.

- Applying Security
Settings:

- Applying Security
Settings: After the security settings have been applied, you can
“View Report” and save for future reference. Click the
“Next” button.

- Complete the IIS
Lockdown Wizard by clicking the “Finish” button.

- Once the Wizard has
been completed, log into the PatchLink Update Web Interface
® Go to the Reports
Menu ® Select the
A-Deployment Test and Diagnostics Package ® Click the Update
Cache to test the package download.

- The icon should
change from
to , as you refresh the browser. If the
icon doesn’t change, contact PatchLink Support to further
troubleshoot the package download.
| |
|