Re: PORTS necessary for surfing?

From: Bjorn (bjornxon@hotmail.com)
Date: 01/03/02


From: "Bjorn" <bjornxon@hotmail.com>
Date: Thu, 03 Jan 2002 10:17:38 GMT

I still have one problem. Now after I've configured it like you said (plus
I opened some other ports) my computer can't renew the IP-lease. I have
Telia ADSL, and use a program called IC-Login for autologin (don't know if
it's important).
Are there some special ports neceseary for renewing the IP? Maybe Telia has
some special thing going on?

- After a reboot it only works for a few minutes.

- If I remove the last rule; "Drop IP Any host -> Any host" and reboot there
is no problem at all.

Any tips?

/Bjorn

"bargepole" <jbhur@hotmail.com> wrote in message
news:vlrY7.154539$KT.39792085@news4.rdc1.on.home.com...
> Habit.
> My rules include some non-NATed entries and I've changed my default port
> allocation to something other than starting at 61000.
> Limiting reply packets' destination ports to >60999 should work.
>
> "Marcel Scherello" <Marcel@Scherello.de> wrote in message
> news:a0svqo$5i5$00$1@news.t-online.com...
> > why do you define your rules for packets >1023 and not for packets
>61000?
> > ...because >61000 is the area of Winroute, you wrote....
> >
> > Thanx
> > Rello
> >
> > > Here's a rule set suggestion to achieve what you want.
> > >
> > > Packet Filter
> > > Incoming
> > > Internet Interface
> > > Permit UDP Any host port=53 -> Any host port>1023
> > > Permit TCP Any host port=80 -> Any host port>1023
> > > Permit TCP Any host port=443 -> Any host port>1023
> > > Drop IP Any host -> Any host
> > >
> > > This rule set will allow DNS lookups, connections to standard HTTP and
> > HTTPS
> > > servers, and block any traffic from anywhere else. FTP, MSN, and mail
> > > connection attempts, for example, will fail until you provide rules
> (above
> > > the last) to allow such communication.
> > >
> > > "Bjorn" <bjornxon@hotmail.com> wrote in message
> > > news:1j5Y7.7262$l93.1866690@newsb.telia.net...
> > > > Hi
> > > > I'm using WinRoute Pro 3.0 on an old PC acting as a firewall and
> router.
> > > As
> > > > I understand it, port 80 is the one used for surfing so what I did
was
> > to
> > > > close almost all incoming ports except for number 80. When I try to
> surf
> > > it
> > > > doesn't work and I can see on the logg-file that it's trying to get
> > > traffic
> > > > on some ports around 61000 so i open some of the up. It works for a
> > while
> > > > but then it stops and I see there's traffic on port 61100 or higher
> > trying
> > > > to get in. It seems to be counting upwards. When i open more ports
it
> > > works
> > > > for a moment but soon it reaches the final open port and i have to
> open
> > > > more. What on earth is this?
> > > >
> > > > /bjorn
> > >
> > >
> > >
> >
> >
>
>



Relevant Pages

  • Re: Help with Iptables on with RH linux
    ... several ports that it listens... ... any established connections are OK. ... If you are dropping packets in the FORWARD chain, ... You can adjust these rules to allow only certain protocols and ports. ...
    (RedHat)
  • Re: Babysitting on iptables requested :-)
    ... Here's the list of ports that I see probed then I take the "Probe my ... this was a friendly probe; all packets were TCP SYNs - ... SYN is a packet that is used to initiate a TCP connection. ... >> between Windows machines, so without this a Windows machine in your ...
    (comp.os.linux.security)
  • Re: Political Analysis of Security Products
    ... > bee collected nor has any evidence of such a backdoor ever really been ... send several packets to ports on the target system. ... be used for booth sides of the security game. ...
    (Pen-Test)
  • RELENG_6_3 ping and DUP packets
    ... duplicate packets when pinging the upgraded machine. ... <ACPI PCI bus> on pcib0 ... usb0: USB revision 1.0 ... 2 ports with 2 removable, ...
    (freebsd-stable)
  • Re: Denied Connection when rule allows
    ... This will work if Authorize.Net always sends the packets back on the same ... ports; if it uses some random, "dynamic" ports for return packets, you will ... ISA machine. ... > connections" from the Authorize.net addresses to our internal network, ...
    (microsoft.public.isa)