Re: Symantec VPN200r - More TCP/UDP Filters

From: Ron Jameson (subscriptions_at_noSPAMsleepysol.com)
Date: 02/12/04


Date: Wed, 11 Feb 2004 19:07:41 -0600

yes, they do work, but have you had any need to get beyond the 5 allowed
filters for TCP & UDP? I think because they don't include the more popular
HTTPS, SSH in the pick list, I need to take 2 of the 5 to allow this thus
leaving me only 3 left. Those got chewed up with symantec's virus download
port, a time port and (doh - kazaa). My UDP are not used as much as TCP,
but I have used 3 of the UDP.

I wish when you utilize the everyone it will INCLUDE everyone no matter
what, that way you can ultimately get 10 of each if you create a group for
the users...but when you create the group and add the MAC's - it ignores the
everyone because you specifically defined a group. This knocks me back down
to 5 TCP & 5 UDP. Granted, I only have this on a small network of under 20
users, but man, if I have this on a larger network, it will be a nightmare
to put in the MAC of all the PC's in a group.

There has got to be an easier way - or give us more access ports.

I use some watchgard SOHO's with clients, but I don't recall the limit there
when you close it all, then open what you need. The beauty of the 200r was
the DUAL WAN port. Watchguards implemention of the fail-over port is lame.
It is not automatic and you cannot run both at the same time which is how I
use the 200r (WAN port to bind SMTP, the other for HTTP usage).

now if only symantec can upgrade the firmware with more flexibility, this
box can be pretty sweet.

"Lars M. Hansen" <badnews@hansenonline.net> wrote in message
news:706k20d168vpajqoujee3r03h2n995rl77@4ax.com...
> On Tue, 10 Feb 2004 20:42:32 -0600, Ron Jameson spoketh
>
> >I have the vpn200r appliance from symantec, blocking all but what is
allowed
> >thru access filters....how do I get more than the 5 additional that is
> >customized? Am I the only one who needs more than 5 IP ports for
everyone?
> >
> >Or, do I need to add the same users to group 1 for 5, then the same users
to
> >group 2 for another 5 and so on?
> >
> >Ron
> >
>
> I'm using the access groups to customize what is allowed among my
> various devices, and it seems to work fine. My only complaints are that
> the "HTTP" selection doesn't include HTTPS, and that "FTP" doesn't work
> with passive FTP.
>
>
> Lars M. Hansen
> www.hansenonline.net
> Remove "bad" from my e-mail address to contact me.



Relevant Pages

  • Re: Open port PIX 501
    ... :i can't open the port in my PIX. ... :I need open the port 1000 to point to the IP 10.254.254.222. ... in practice only DNS servers doing zone transfers need tcp. ... of UDP, it would be a highly unusual client which did not stick ...
    (comp.dcom.sys.cisco)
  • RE: DNS Records
    ... tcp>1023 53 Client queries with long replies ... On other client types, ... if you lock down all but port ... a client queries an initial server from an unreserved port number to UDP ...
    (Security-Basics)
  • Windows Update Scrammed My Server
    ... The Simple TCP/IP Services could not find the TCP Echo port. ... The Simple TCP/IP Services could not find the UDP Echo port. ...
    (microsoft.public.windowsupdate)
  • Re: Settings for Mercenaries and MS MN500 Wireless Router
    ... When you type "27960-27960 tcp and udp" exactly where are those entries ... Enable Description Outbound Port Trigger Type Inbound Port Public Type ... > inside the game. ...
    (microsoft.public.games)
  • Re: using routers ACL to substitute firewall
    ... > You can handle TCP responses with a statement such as ... > systems have any programs that dynamically allocate UDP source ... > packets with a UDP source port of 137, ... > For incoming connections, UDP is again a problem, in that UDP ...
    (comp.security.misc)

Quantcast