Re: Firewall and Home Network

From: Robert R Kircher, Jr. (rrkircher@hotmail.com)
Date: 11/20/02


From: "Robert R Kircher, Jr." <rrkircher@hotmail.com>
Date: Wed, 20 Nov 2002 08:26:14 -0500

ThomBa wrote:
> I really must say that the previous two responses were some of the
> best and down to earth I have seen in this forum. Thanks.
>
> Now, as a newbie to this, where can I learn more on how to configure
> firewalls starting from the ground?
>
> I am using a D-Link 300I ADSL-modem and D-Link 704P Router/FW with
> filter for in and outbound traffic. But, as stated previously, I
> really do not know how to configure it. According to D-Link support,
> the default is to to block all incomming connection attempts.
>
> How do I track and manage outgoing traffic?
>

<Reposted to avoid Top Posting confusions>

Here is exactly where most of these Desktop Firewall have an up on a HW
solution. All the DT FW's I've tested notify you what applications trying
to access the internet and on what port using what protocol. All you need
to do is choose allow or deny the traffic to pass. The advantage is you
don't need to know what port or protocol is being used, you only have to
know that you just launched your email program and now you FW is asking if
it's ok to let the traffic pass. The down fall to this approach is the
unknowing user may not make the right choice or worse may simply choose
"allow" for all apps (including malicious ones) that try to access the
internet. This, of course, completely defeats the purpose of having a
firewall.

With that all said, you'll want to start out by opening a few basic ports
HTTP (80) for web browsing, POP3 (110) and SMTP (25) for email, NNTP(119)
for news readers/Usenet, and go from there. Experiment. Launch your browser
or other internet applications and start hunting for the proper protocols
and port # to use in you rules. If you run up against an app that doesn't
connect then go out to their support page or come here. If you're lucky
your router has the most popular protocols reconfigured and then all you
have to do is find out which one to use. Most popular applications and
Games have firewall instruction someplace in their support forums, you just
have to do some hunting.

Once you've found all the protocols/ports you need to open and create rules
to allow traffic, remember that you've opened up holes in your firewall that
someone may exploit. This is why David's advice of a good logging tool can
be important. You can periodically review the logs and look for strange
patterns in the log and/or strange IP addresses. We could start a whole
other thread on how to read and interpret these log files. Also keep in
mind that many games want a range of ports open. The bigger the range the
larger the hole is to exploit.

The nice thing is once you've done the work and configured the FW correctly
you don't really have to revisit it. Review the logs every so often and
periodically open and close ports that you don't use on an everyday basis.
For example, I have rules for VCN (a remote desktop app) and Kazaa which I
only turn on when I am going to use the applications. Otherwise they are
off and remain that way.

--
Rob


Relevant Pages

  • Re: Strange WAN Activity
    ... > firewall logs for a possible TCP FIN scan that keeps ... > company's intranet server IP and its port 80 across our ... > My firewall is a Sonicwall Pro 200 and I'm running W2K ... It's difficult to be sure without inspecting the web server for signs of ...
    (microsoft.public.win2000.security)
  • Re: How do I block just one port from being listened to on my server
    ... Well I looked through ALL my logs; ... Well I'll be testing that Firewall out that you gave the link to. ... I just don't want it blocking everything by ... Blocking one port isn't the answer. ...
    (microsoft.public.security)
  • Re: Identifying Internet Attacks
    ... contain the hacker to a particular machine, leave the machine on the network ... Some firewall software such as ... open ports; however, this will not identify which program is using the port. ... firewall logs, the IIS web and ftp server logs and Windows security event ...
    (microsoft.public.inetserver.iis.security)
  • Re: false portscan alarm
    ... What is the reason of that treffic? ... and the browser and/or the "personal firewall" had decided to close those ... which each have a local source port above 1024 opened outgoing to port 80 ... I've had a dig through my own PIX logs, and while there is nothing for today ...
    (comp.security.firewalls)
  • Re: Firewall and Home Network
    ... >>> that PC should have a firewall installed. ... to access the internet and on what port using what protocol. ... You can periodically review the logs and look for strange ...
    (comp.security.firewalls)

Quantcast