RE: Windows XP open port 389

From: Zimin, Alex (alex@towerrecords.com)
Date: 03/13/02


From: "Zimin, Alex" <alex@towerrecords.com>
To: "'Williams, Kevin'" <KWilliams@sark.com>, "'Patrick Nolan'" <pnolan01@nycap.rr.com>, focus-ms@securityfocus.com
Date: Wed, 13 Mar 2002 11:09:27 -0800

As I understood article refers to the MS Proxy Server configuration.
Internet Connection Sharing in WIN XP should use NAT (Network Address
Translation) not the proxy technology.
http://www.microsoft.com/windows2000/en/server/help/default.asp?url=/WINDOWS
2000/en/server/help/sag_RRAS-Ch2_8.htm

-----Original Message-----
From: Williams, Kevin [mailto:KWilliams@sark.com]
Sent: Wednesday, March 13, 2002 9:20 AM
To: 'Patrick Nolan'; focus-ms@securityfocus.com
Subject: RE: Windows XP open port 389

I believe the Internet Locator Service (ILS) cannot be installed on Windows
XP Professional.

-----Original Message-----
From: Patrick Nolan [mailto:pnolan01@nycap.rr.com]
Sent: Wednesday, March 13, 2002 9:23 AM
To: Williams, Kevin; focus-ms@securityfocus.com
Subject: Re: Windows XP open port 389

>
> Does anyone have any info on why ICF was listening for LDAP traffic? I
> didn't have any services configured, only ICMP allowed.
>
Possible explanation, the article does not say "listening" re port 389.

389 Internet Locator Service (ILS) TCP

Pat

http://www.microsoft.com/windows/NetMeeting/Corp/reskit/Chapter4/default.asp
Establishing a NetMeeting Connection with a Firewall
When you use NetMeeting to call other users over the Internet, several IP
ports are required to establish the outbound connection. The following table
shows the ports, their functions, and the resulting connection.

Port Function Outbound Connection
389 Internet Locator Service (ILS) TCP
522 User Location Service TCP
1503 T.120 TCP
1720 H.323 call setup TCP
1731 Audio call control TCP
Dynamic H.323 call control TCP
Dynamic H.323 streaming Real-Time Transfer Protocol (RTP) over UDP

If you use a firewall to connect to the Internet, it must be configured so
that the IP ports are not blocked.

To establish outbound NetMeeting connections through a firewall, the
firewall must be configured to do the following:

Pass through primary TCP connections on ports 389, 522, 1503, 1720, and
1731.
Pass through secondary TCP and UDP connections on dynamically assigned ports
(1024-65535)."



Relevant Pages

  • Re: Using Remote Desktop From an SBS Domain
    ... when you tried to RDP while attached directly to a port on your router? ... Internet to initiate an IP conversation with your computer. ... This situation is different than if you ran your own NAT connection sharing ...
    (microsoft.public.windows.server.sbs)
  • RE: Configure Hardware Firewall for SBS 2003
    ... the corresponding ports to the SBS box. ... When a router is deployed at the SBS end, you must forward the port numbers ... TCP 110 This port is used for POP3 mail clients. ... TCP 1723 PPTP VPN connection ...
    (microsoft.public.windows.server.sbs)
  • Re: Using Remote Desktop From an SBS Domain
    ... I don't have much experience with this type of Internet access (at least not ... allows all "outbound" traffic from your private network to flow freely to ... UDP port (synchronize time with an external Network Time ... Hopefully next week I can attempt a connection while my ISP watches the ...
    (microsoft.public.windows.server.sbs)
  • Re: Yet another thread on the legality of port scanning
    ... Yet another thread on the legality of port scanning ... >> information transfer on the internet. ... >> is an acceptable connection in the absence of explicit permission? ... > pen testing experience in our state of the art hacking lab. ...
    (Security-Basics)
  • Re: 45 days STUCK LIKE CHUCK. DNS / Mx record cant recieve emails
    ... cable from the Comcast router and plug it into that machine, ... Yes router is connected directly into the internet nic / other nic ... You can test the connection from within the LAN, ... I'm thinking that leaves the NAT device blocking port 25. ...
    (microsoft.public.windows.server.sbs)