NIS2002: Adding rule for port does not work

From: Markeau (please_reply@news.group)
Date: 03/25/03


From: "Markeau" <please_reply@news.group>
Date: Tue, 25 Mar 2003 12:04:40 -0600

Trying to simply view Trackercams http://www.trackercam.com/index1.htm
... some use various ports, 8090 being one of the most popular. The
NIS2002 event log shows 8090 blocked (I added a rule at the very
bottom of the list to block all) so I add a new rule to permit 8090
but that rule is overlooked - the event log shows the block all rule
is blocking 8090. I even modified the rule for both in/out and
local/remote 8090 and tracked the rule but NIS2002 never sees it.

Example event log entry:

Rule "BLOCK ALL" blocked (24.232.190.146,8090). Details:
Outbound TCP connection
Local address,service is (localhost,1753)
Remote address,service is (24.232.190.146,8090)
Process name is "C:\Program Files\Internet Explorer\iexplore.exe"



Relevant Pages

  • Re: [Full-Disclosure] Possible Comprimised IIS 5 on Win2k help
    ... You need to enumerate the ports the machine listens on, ... running processes, filesystem timestamps, Event Log, logged in users, ... Filesystem timestamps can be useful to help you locate the approximate ...
    (Full-Disclosure)
  • Re: trying to publish a video conferencing system
    ... our Lifesize VC system behind a firewall and also connected directly to ... betrifft das die Ports ... I read this in the event log. ... create a publishing rule that publishes the port range from 1024 to 65535. ...
    (microsoft.public.isa.publishing)
  • Firewall exceptions disappear.
    ... we have a batch script that will open up all ... the ports and allowed programs that our system requires. ... I haven't actually looked at the system yet to see what ports/programs ... I was told there was nothing in the Event Log either (no ...
    (microsoft.public.windowsxp.security_admin)
  • XP SP2 and ports required to view a remote event log
    ... I need to know what ports are required to be opened on a XP SP2 computer to ... remotely view its event log. ... Eddie ...
    (microsoft.public.windowsxp.setup_deployment)