Re: Windows File Sharing with IPCop

From: j.mickerts@gmx.net
Date: 08/22/02


To: "Bryan Ponnwitz" <bponnwit@btboces.org>, <focus-ms@lists.securityfocus.COM>
From: j.mickerts@gmx.net
Date: Thu, 22 Aug 2002 20:26:33 +0200

Hi,

basically, you should be able to telnet port 445 on the windows host from
the same network. The same should be true from the other side of the
firewall. If it does not work, you should first check whether it is just a
simple routing problem. To check this you should allow icmp to ping the
server. If that works, or you can access any other service on the machine,
this is done. If you can forward other ports, but not 445, you still may
have the firewall blocking this for some reason. Then you should really
check the logs of the firewall, and maybe share some information found
there. You should consider to allow kerberos (Port 88 upd/tcp) as well.
Even if you do IP-Filtering Kerberos will be allowed by default, and
somehow you should authenticate. One way if Lanman (137+138upd, 139tcp),
the other is Kerberos.

For PPTP I assume you allowed port 1723 but forgot to allow GRE, which is
IP Protocol 47 (do not mess this up with tcp or upd ports).

Kind regards,

Jens Mickerts

"Bryan Ponnwitz" <bponnwit@btboces.org>
22.08.2002 15:32

To
<focus-ms@lists.securityfocus.COM>
cc

Subject
Re: Windows File Sharing with IPCop

I listened to your advise and here are the following changes that I
made:

1) I changed the SSL server running on the firewall to run on port 443
instead of 445 to avoid any confilct.
2) I attempted to open ports 135-139 udp and tcp and there was no
effect.
3) To see if I needed RPC or not, I enabled IP Filtering on the WinXP
machine and only allow port 445 for tcp and udp. I'm able to connect to
the test share I have setup with no problem from within the firewalled
network, but still cannot connect externally.

Any more ideas at this point? It would appear that all I have to do is
forward port 445 for it to work. So, I instead tried to setup the WinXP
machine to accept incoming PPTP connections so that I can connect that
way. But when I try to connect to the computer via PPTP, I get one of
the following errors:
1) TCP/IP reported error 733: Your computer and the remote computer
could not agree on PPP control protocols.
2) Error 6: The handle is invalid.
3) Error 668: The connection was terminated.

Now what the heck is the problem?

Bryan Ponnwitz
Webmaster - Broome-Tioga Boces
bponnwit@btboces.org
(607) 763-3609



Relevant Pages

  • Re: Turning on Media Sharing in WMP11
    ... I believe it forms quite a reasonable network media device. ... Turning on SSDP (it was disabled as was uPnP) to Manual and then UPnP ... If there is a firewall, or NAT, built into your ... You need to open port s: ...
    (microsoft.public.windowsmedia.player)
  • Re: May need to move from SBS because of connection issues
    ... Just to make sure you are clear regarding port 4125, ... access remote systems and you are behind a firewall on a non-SBS network, ... established that RWW worked TO your SBS network from outside. ... have been proof that the required ports were forwarded to the SBS server. ...
    (microsoft.public.windows.server.sbs)
  • Re: Identifying Internet Attacks
    ... contain the hacker to a particular machine, leave the machine on the network ... Some firewall software such as ... open ports; however, this will not identify which program is using the port. ... firewall logs, the IIS web and ftp server logs and Windows security event ...
    (microsoft.public.inetserver.iis.security)
  • Re: Leopard Firewall Warning
    ... machines on a particular network can access a port. ... The new scheme is an XP-style application based firewall; ... This, as an example, allows an attacker, once ...
    (uk.comp.sys.mac)
  • Re: keeping ports open
    ... If a port is open, it means that 1) a software or service is running on your ... and 2) you're not using a firewall or your firewall isn't ... Use firewall software and hardware and antivirus software that is ... Follow the instructions for hardening Windows and IIS at ...
    (microsoft.public.security)