Re: How secure is to open ports from inside the firewall?



MIHO the outbound filtering is as important or more important then the inbound filtering. This is due to the fact that many exploits are using legal traffic to get in e.i. malformed port 80 requests to a web server, to force the web server to connect out. Your firewall should block the web server from connecting out.
In outbound filtering you should first block everything then allow as little as possible and make your permissions as tight as possible. If you need to open for port 53 traffic. Allow only outgoing DNS protocol type traffic to the specific DNS server and only for IP addresses which possibly need to do DNS look ups.

Regards
Kim Guldberg
GFCW, CPSA


Iosif Gasparakis skrev:
Hello list.

One silly question: How secure is to open ports from inside the firewall?

Ok, closing incoming ports is the purpose of a firewall. But what about the outgoing? Could this make someone's life who already broke into the network easier? Or is it already too late, and that someone if already in can use just any open port to send traffic out?

Please let me know your views.

Joseph





___________________________________________________________ The all-new Yahoo! Mail goes wherever you go - free your email address from your Internet provider. http://uk.docs.yahoo.com/nowyoucan.html




Relevant Pages

  • Re: yahoo dsl + home web server
    ... > I am trying to set up a web server at home and I am having a bit of an ... > port forward all traffic to port 80 to the internal ... How do you think a remote box would be able to find your LAN? ... will perform a DNS request and will neither be able to find your network IP ...
    (comp.os.linux.networking)
  • Re: RE: application for an employment
    ... Using a web server is NOT a port scan - in any manner. ... To alleviate some ignorance regarding the DNS process and public servers. ... This is NOT if anyone can connect to port 53 and use them. ...
    (Security-Basics)
  • Re: IP routing with remote DNS, but server & client on same subnet - how?
    ... I clicked on the file link -- and it timed out, server ... I believe there is more than just DNS. ... DNS replies with the IP address of a registrar's web server. ... Browser connects to your.public.ip.address on port 32004. ...
    (comp.os.linux.networking)
  • Re: Web server and DMZ
    ... How can I set things up so that I can have web requests go to an external IP and yet have eMail come to the SBS server. ... Plug the web server into another port on ... Configure the router to forward port 80 to the webserver, ... put whatever web server name you want into his DNS, ...
    (microsoft.public.windows.server.sbs)
  • Re: Tips on blocking difficult services..
    ... you can run all of these protocols over any port you want. ... Sebastian is quite correct. ... It is a false statement to say that outbound filtering is nonsense. ...
    (comp.security.firewalls)