Re: "BAD" local ports

From: Purl Gurl (purlgurl_at_purlgurl.net)
Date: 06/18/04


Date: Thu, 17 Jun 2004 21:38:24 -0700

Brendan DJ Murphy wrote:

 
> I have configured my firewall to block all INCOMING packets TO what I
> consider to be "Bad" ports
 
> 135
> 445
> 2745
 

There is a much easier solution. Close all ports
you do not need, which, if you are not running
services, can be counted on one hand. For some
firewalls, you do not need any incoming open ports.

Our servers only have a combined total of four open
ports and all services run just fine and dandy.

Common ports you might need,

port 21, port 80, port 110 and port 443

ftp, http, pop3 and SSL (secure http)

Some news servers require port 119 but
not too often. I have found those which
poll your port 119 do not absolutely
require a poll response.

Close all ports then open those you discover
your system needs to operate correctly.

Here is yet another list of ports and their usage,

http://www.networksorcery.com/enp/protocol/ip/ports00000.htm

Purl Gurl



Relevant Pages

  • Re: Root exploit for FreeBSD
    ... for two ports to my FreeBSD portscluster nodes. ... and it gives the firewall ... US this is also quite common, at least with regards to University ... if your computer is going to connect on our network it must be configured in certain ways and behave "normally" or you won't get a connection. ...
    (freebsd-questions)
  • Re: Root exploit for FreeBSD
    ... for two ports to my FreeBSD portscluster nodes. ... and it gives the firewall ... US this is also quite common, at least with regards to University ... if your computer is going to connect on our network it must be configured in certain ways and behave "normally" or you won't get a connection. ...
    (freebsd-current)
  • Re: Trouble accessing Outlook Web Access from behind firewall
    ... When starting the firewall I also set ... > rejected and dropped packets are logged, however I see nothing in my log ... > # Higher ports needed to accept incoming/outgoing calls ...
    (comp.security.firewalls)
  • Re: iptables configuration
    ... >> that if a 'virus/trojan' initiated a connection to the net, the firewall ... >> would not protect the LAN. ... The LAN is NATed with private IPs to one public IP. ... the ports that are used by services running on linux. ...
    (comp.os.linux.security)
  • Re: Norton Personal Firewall 2003
    ... |> First thing I would do is put the GRC test site into the Exclusions ... | ports they will not get the same result being in my blocklist, ... the firewall checks unsolicited inbound communications attempts. ...
    (comp.security.firewalls)