Re: strange messages

From: Christopher Schulte (christopher@schulte.org)
Date: 03/08/01


Date: Thu, 08 Mar 2001 13:12:41 -0600
To: Brooks Davis <brooks@one-eyed-alien.net>, "oldfart@gtonet" <oldfart@gtonet.net>
From: Christopher Schulte <christopher@schulte.org>

At 10:35 AM 3/8/2001 -0800, Brooks Davis wrote:
>but the ports RPC services bind to are the same ones your outbound
>TCP connections are bound to so you'll need stateful firewalling
>to make it work.

You can convince the kernel to use a more user-defined port range(s) for
dynamic outbound connections with a few sysctl vars, thus making firewall
confs a bit easier to craft and maintain:

`sysctl -a | grep portrange`

>You can force NFS to use only it's reserved port
>(see /etc/defaults/rc.conf), but generally you can't dictate where RPC
>services bind. You're best bet is to disable rpc.statd unless you are
>actually using it.

It's always a good idea to turn a service off if you're not using it. ;p

>-- Brooks
>
>--
>Any statement of the form "X is the one, true Y" is FALSE.
>PGP fingerprint 655D 519C 26A7 82E7 2529 9BF0 5D8E 8BE9 F238 1AD4

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • Re: Will Exchange using nonstandard port cause problems with Sharepoint?
    ... about changing the std outbound port of Exchange. ... 'SmallBusiness SMTP Connector'. ... Next, click on the Advanced tab, then Outbound Security,, then Basic ...
    (microsoft.public.windows.server.sbs)
  • RE: Unable to print on ports 9100/515
    ... Is the protocol definition for outbound on port 9100 and 515 actually trying ... > the detailed steps to publish a TCP/IP network printer through ISA, ... > 306071 How to Publish a TCP/IP Printer Behind ISA Server ...
    (microsoft.public.windows.server.sbs)
  • Re: Outbound ports
    ... Destination Port 80 outbound ... I would never allow more than port ... >resource need) (or inbound for the DMZ). ... arguing that you meant "outbound from the WAN to the DMZ"? ...
    (comp.security.firewalls)
  • Re: [Newbie alert!] Is the Linksys BEFSX41 hardware Firewall/router a "real" firewall?
    ... there is very little that a real firewall appliance will ... ALL inbound and outbound traffic in real time - a simple KVM switch will ... outbound SMTP then it can spam all it wants. ... Private Ports in some versions - where you can list port ranges to block ...
    (comp.security.firewalls)
  • Re: IPSec policie is not working like it should
    ... outbound have to be enabled. ... > I'm not sure how you can force all your traffic to go out a single port. ... > Almost all of your applications are going to be given dynamic outbound ... Outgoing mail is certified Virus Free. ...
    (microsoft.public.windows.server.networking)