Re: [fw-wiz] RE: Help w/ Port 137 Traffic

From: Luca Berra (bluca@comedia.it)
Date: 10/14/02


From: Luca Berra <bluca@comedia.it>
To: firewall-wizards@honor.icsalabs.com
Date: Mon Oct 14 08:12:15 2002

On Sun, Oct 13, 2002 at 02:40:59PM -0400, R. DuFresne wrote:
>
>
>depending upon the kinda of windows OS' behind your firewall, you might
>wish to add 135-139, tc and udp, as well as 445, and 1433,1434. Of course

if you really want to block outgoing traffic from workstation put a
proxy in the middle....

>> I have to add one clarification to the scenario and apologize for not
>> including this up front: could running Samba (as a master browser/file
>> server - not domain controller) be the source of the problem? Are there
>> some outbound ports I should be blocking when (I assume) Samba announces
>> itself periodically as the master browser?
samba announces itself periodically on the broadcast address of all
connected interfaces and to addresses specified with the 'remote
announce' smb.conf parameter.
I don't believe samba uses netbios-ns lookups to resolve remote hosts
connecting, but anyway noone should be connecting to your samba server
from outside.

as a last note i am also getting many probes on port 137 and 139, but
they seem unrelated, i might try answering to netbios-ns lookups and see
what happens, if i find a smaller beast than samba to use, that is.

L.

-- 
Luca Berra -- bluca@comedia.it
        Communication Media & Services S.r.l.
 /"\
 \ /     ASCII RIBBON CAMPAIGN
  X        AGAINST HTML MAIL
 / \


Relevant Pages

  • Re: [SLE] Some Samba Client Issues
    ... Ever since I have started using SuSE 10.0 I have had troubles with connecting to Windows PCs using samba. ...
    (SuSE)
  • Re: trying to mount SMB
    ... If the machine that's connecting to the server is named "kong", ... Which version of Samba is the server running? ... SMB shares from a pretty recent smbd while using a very old version ...
    (comp.os.linux.misc)
  • Re: Need advice for Samba/ZFS/NFS
    ... But it did not get me into the gore of samba or indicate what are the ... I haven't read the specs to see what bugs are fixed, ... I've had decent luck connecting to ... a Windows "workgroup", a similar but entirely different concept. ...
    (comp.unix.solaris)
  • Re: New SuSE 9.1 User
    ... >> no trouble connecting to the Internet via my cable modem (wired LAN ... > Samba is a breeze to configure from within Suse 9.1 Pro. ...
    (alt.os.linux.suse)
  • Re: Samba - XP Home in peer-to-peer mode
    ... It now looks like an XP issue (*grumble, ... XP Home, grumble, grumble*) rather than a Samba issue, details below. ... > If you want your XP machine be local master uncomment the line above. ... Connecting to the XP machine still works as before. ...
    (Fedora)