Re: IPSec and Passive FTP

From: \ (dvader_at_deathstar.mil)
Date: 11/15/03


Date: Sat, 15 Nov 2003 10:32:42 -0500


>This is one good example showing why IPSec alone does not make for a
>good firewall. The best way to go about it with IPSec is to block any
>high ports that you have static services listening on and allow high
>port-to-high port on the rest.

I get the picture, but not the method. How do you specify "high ports?" As far
as I can tell, I can only set single ports, one at a time, or all ports.

>Allowing a whole range of ports which do
>not have services listening on them does not expose your whole system.
>The best way to deal with FTP is to use a connection tracking firewall
>that has an alg which only allows for such connections in response to
>ftp port commands.

Yeah, I'm just trying to learn about IPSec, including its limitations. I have a
real firewall. :-)

-- 
Dave "Crash" Dummy - A weapon of mass destruction
crash@gpick.com
http://lists.gpick.com


Relevant Pages

  • Re: VPN not working when client behind another firewall
    ... The latest is that we have tested the ports and GRE ... >place a hardwarebased firewall router out in front of SBS ... This area is NAT-T over IPSec across ... >server to work when behind a NAT. ...
    (microsoft.public.windows.server.sbs)
  • Re: Closing Open Ports
    ... open up a whole lot of ports you didn't really want to open. ... or virus could potentially disable IPsec. ... By comparison, the XP ICF firewall ... a TCP/IP filtering expert and can troubleshoot setup problems without a log ...
    (microsoft.public.win2000.security)
  • Re: Dateien kopieren
    ... > IPsec Firewall alles blockiert. ... Du mußt soviele Ports öffnet, dass sich die Sinnfrage der Firewall ... IPSec-Verbindung auf den Server herstellen. ...
    (microsoft.public.de.german.windows.server.general)
  • Re: IPSEC
    ... > IPSEC works differently than a firewall in that a firewall will allow ... > IPSEC will not allow any inbound traffic regardless of the origin, ... > in lieu of individual rules denying traffic on specific ports. ... If deny all rule is there then ALL ports except for those specifically ...
    (comp.security.firewalls)
  • Re: 2003 to nt4.0 trust
    ... Do you have high ports opened in your ... If you haven't set up the firewall to lock in rpc ports ... I keep getting no logon servers available. ...
    (microsoft.public.windows.server.active_directory)