Re: Port forwarding/open ports?




AV wrote:
> To be able for another person to connect to my Netmeeting (conf.exe)in
> Windows XP and share applications I would need to open the ports 1720
> and 1503 in my router firewall.

ok

> My wonder is how much more vulnerable I will be if I do that? It would
> be nice not to have to open and close those ports over and over again in
> my router firewall when I need it and instead having them open all the
> time so it will just be to start Netmeeting when I need to collaborate
> and share applications.

good idea. that is just as safe or unsafe as what you mentioned above.
But it is more convenient. As long as you only have netmeeting running
when you need it.

you could improve it by setting your "home routers" firewall to only
allow your friend's ip to connect. nobody else. but then if your
friends ip changes, it's a nuisance. I think many broadband IPs tend to
remain constant for ages, prob depends on the provider.

> - Is it just a risk (bigger or smaller?) when I have Netmeeting started
> since I suppose some good hacker would need an application that actually
> listens to those open ports to be able to do anything?

I think what you wrote there doesn't make sense

>If I normally
> don't have Netmeeting started I suppose the ports could just as well be
> open in my router all the time?
>

correct, good idea.


> - If it is a risk as described above, what if I create a rule in my
> software firewall that blocks those two ports on the computer in my LAN
> to which the ports are forwarded? It is quicker for me to put that rule
> on and off in my software firewall than to open and close the ports in
> the router.

part of what you wrote there doesn't make sense. But you're hintin
towards a good idea.
Set your firewall to block everybody from connecting , except for your
friend's IP.
then even if you did have netmeeting open all the time, and ports
forwarded by your router permanently, your firewall would (try to)
protect your computer. Pretty safe. Safest thing is that + not having
netmeeting running all the time.
I think it's unnecessarily to go to the lengths you showed some
distaste for, the idea of setting port forwarding each time you want to
use netmeeting. Better to just run netmeeting when you need it.


> - These same questions above goes for the one port one can choose to
> have open in the router to give the best possible chances for good sound
> quality for Skype IP calls. How risky or not is it to have a few ports
> open in you router firewall?

same. if the software isn't running then it's certainly ok.

I guess that if your comp was exploited then malicious software could
use those ports though. so perhaps not so safe. to have loads of ports
forwarded. At he same time it may nto be so feasible time wise to keep
forwarding the right ones each time you use the software. it's a
compromise

.



Relevant Pages

  • Re: What is broken:McAfeee firewall or my router ????? Urgent, ple
    ... your computer regardless of what McAfee firewall said. ... If your router is ... warned about those ports being available right away if you had any of those ...
    (microsoft.public.security)
  • Re: What is broken:McAfeee firewall or my router ????? Urgent, ple
    ... your computer regardless of what McAfee firewall said. ... If your router is ... warned about those ports being available right away if you had any of those ...
    (microsoft.public.security)
  • Re: How to stealth against ping/echo requests?
    ... I just started using the Online-Armor firewall. ... Some ports are even open. ... Are you behind a router? ... Every time it founds a new LAN, it asks if you want to trust it ...
    (comp.security.firewalls)
  • Re: FIREWALL- worth the effort ?
    ... I only use internet intermitently and "pull the plug out" ... Do you have a home Cable/DSL Router? ... forward any ports from the outside world to your Macthrough ... The other function of a firewall is to prevent out bound ...
    (comp.sys.mac.system)
  • Re: adsl router security
    ... ]>used the virtual server feature to route packets on ports 21 and 80 to the ... ]>running ssh and mysqld but no other network services. ... if you can if the router is programable ... Remember all a firewall does is to prevent certain packets getting ...
    (comp.os.linux.security)