Re: [fw-wiz] outbound traffic security risk

From: Mitchell Rowton (mrowton_at_bdo.com)
Date: 03/23/04

  • Next message: Devdas Bhagat: "Re: [fw-wiz] outbound traffic security risk"
    To: <devdas@dvb.homelinux.org>, <firewall-wizards@honor.icsalabs.com>
    Date: Tue, 23 Mar 2004 11:25:35 -0500
    
    

    <snip>

    Ahem! ISPs are /not/ corporate providers. They should NOT be blocking
    stuff (currently, NetBIOS and a bunch of MS ports exempted, and port
    25
    outbound, but thats a different beast.)

    </snip>

    Thats why i gave an example of how an ISP can't block http but should
    block msrpc and sql, sounds like we are on the same page but the "Ahem!"
    leads me to think you are disagreeing..?

    I think some ISP's which are focused toward non-technical users could
    (and do) add value to their service by providing basic filtering and
    protect users from the above example ports. This should of course be
    agreed upon by the customer before filtering. In most cases, most
    customers, would want a minimum amount of protection.

    You shouldn't think of this as taking away your rights and freedom on
    the internet to not be filtered. I chose my ISP because I didn't want
    to be filtered, and they don't filter. But I wouldn't agree with a
    general statement that ISPs should NOT be blocking stuff. Users should
    have the option of having a minimum amount of protection, they should
    have the option of choosing an ISP that provides this service. If more
    users chose ISP's that provide this service then entire categories of
    risks on the internet would be mitigated significantly.

    NOTICE:
    The contents of this email and any attachments to it may contain privileged and confidential information from BDO Seidman, LLP. This information is only for the viewing or use of the intended recipient. If you are not the intended recipient, you are hereby notified that any disclosure, copying, distribution or use of, or the taking of any action in reliance upon, the information contained in this e-mail, or any of the attachments to this e-mail, is strictly prohibited and that this e-mail and all of the attachments to this e-mail, if any, must be immediately returned to BDO Seidman, LLP or destroyed and, in either case, this e-mail and all attachments to this e-mail must be immediately deleted from your computer without making any copies thereof. If you have received this e-mail in error, please notify BDO Seidman, LLP by e-mail immediately.

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Devdas Bhagat: "Re: [fw-wiz] outbound traffic security risk"

    Relevant Pages

    • Re: [fw-wiz] outbound traffic security risk
      ... > protect users from the above example ports. ... > agreed upon by the customer before filtering. ... My ISP blocks, and charges money to be unblocked. ... > general statement that ISPs should NOT be blocking stuff. ...
      (Firewall-Wizards)
    • Re: Notifying user of open Internet access
      ... > by filtering out Netbios from the Internet, ... Ha Ha Ha - I already have spam and content filtering on my mail server, ... There is nothing in blocking ports 135-139,445 that could remotely be ...
      (alt.computer.security)
    • Re: IPSec for Packet Filtering
      ... Blocking just a few ports doesn't make for a very effective security ... evidence there of who did it, or you suspect your filtering is blocking ...
      (microsoft.public.security)
    • Re: Cutting p2p connections on common used ports
      ... In that case I am totally against you blocking /any/ ports. ... blocks port 25 on home connections not caring that I need to get send ... An ISP provides a connection to the internet, ...
      (alt.os.linux)
    • Re: firewall trick for faster BitTorrent downloads
      ... Check with your ISP, they may be blocking Bittorent. ... Many Large ISP's are blocking P2P ports and some have layer 4 ... Connection -> Transport Encryption ...
      (Fedora)