Re: IDS Management - Port Numbers

From: Brian (bmc@snort.org)
Date: 12/13/01


Date: Thu, 13 Dec 2001 14:16:52 -0500
From: Brian <bmc@snort.org>
To: robert.d.turner@bt.com

According to robert.d.turner@bt.com:
> Does anyone know of a list of recognised (standard) port numbers for IDS/
> Firewall/Management applications? I've been looking around intermittently
> for a while, and there does not seem to be a collected list.

Older RealSecure installations listened on 2998 and 901 by default.
The port is reconfigurable. The standard encryption plugin has the
banner:
   ISS ECNRA Built-In Provider, Strong Encryption Version

Dragon uses encrypted ICMP tunnels. I've taken down my test dragon
sensors at work, so I don't know what types & codes they use.

Most vendors recommend having a seperate network for administration
and data transfer for your remote sensors. Where this is not
available, I suggest using vtun, ipsec, or any other strong encryption
VPN.

-- 
"Why does everyone always pick on Attila as the archetypal right wing
nutcase?"  "Attila is less hated than Hitler, better known than Franco,
and lacks Mussolini's comic charm." -- Ben Aveling and Bill Cole, ASR



Relevant Pages

  • Re: How to setup trust between 2003 SP1/R2 and MIT 1.4.3 ?
    ... It works when I change the encryption types in krb5.conf to only ... to opensuse.suse.home (no port 88 traffic) ... Protocol: IP ... NOT a forwarded ticket ...
    (comp.protocols.kerberos)
  • Re: Using a home T-1 line to evade company filtering
    ... She just simply set the listening ports on her machine to port ... to outwit the boss. ... uses SSL/SSH encryption between her machine and my computer in Australia. ...
    (comp.security.firewalls)
  • Re: Elliptic curves
    ... It is a "standard" which the SECG group (a self-appointed group, ... Turning a key-exchange system into an asymmetric encryption system is ... symmetrically encrypt your message with that session key. ... basically turns RSA encryption into a key exchange system). ...
    (sci.crypt)
  • Re: How to set multiple SMTP ports?
    ... port 26 doesn't belong anywhere near a computer serving other people. ... Proposed Standard RFC doesn't get reclassified as a Draft Standard, ...
    (comp.mail.eudora.mac)
  • Re: Old HP Printer & Win XP
    ... It is basically the old Centronics standard. ... Bi-directional in reference to the parallel port means data can flow ... Your printer should operate normally at the SPP setting. ... If you look up the Win2k driver for the 855c on the HP site, ...
    (comp.periphs.printers)