Re: Why a software firewall?

From: jch (JCH_at_nospam.com)
Date: 07/10/04


Date: Sat, 10 Jul 2004 13:16:56 -0400


"CyberDroog" <CyberDroog@ClockworkOrange.com> wrote in message
news:9u10f0te6c6437vp30l5dac0n2cma4996i@4ax.com...
> On Fri, 09 Jul 2004 23:40:55 GMT, Duane Arnold <notme@notme.com> wrote:
>
> >I have certainly seen a couple probes come through the Linksys router at
> >port 1434 SQL server like the NAT router was not even there. The port was
> >not being forwarded either. BlackIce didn't react on the desktop or
> >laptop for no reason and reported the events with the desktop that is on
> >24/7 and the laptop that was on 24/7 at the time both having SQL Server
> >running. I have also seen at least on other person report on a probe
> >coming past the NAT router.
>
> Haven't you already dealt with problem ports? I have 1433-1434 forwarded
> to a non-existent IP on the NAT router. But I don't recall ever seeing
> probes on those ports hit the software firewall before I did that.

Then why did you do that?



Relevant Pages

  • Re: 0.0.0.0 Probes
    ... I recommend setting up acl on the router with anti-bogon list so that not ... but you can drop packets for any ip block that ... Subject: 0.0.0.0 Probes ... > Over the last few days my external NIDS (outside firewall) has picked up ...
    (Security-Basics)
  • Re: Ports getting hammered?
    ... If you have closed the ports and ZA is not responding, ... NAT router and I have had that happen on a Linksys I owned that didn't have ... SPI, which BlackIce I was using at the time blocked the probes. ...
    (comp.security.firewalls)
  • Re: Allow internet traffic for self build programs in Norton Personal Firewall
    ... > The port scans are from public IP's. ... There is nothing to say that a probe cannot come past a NAT router that's ... as I have seen it happen on my network as well a couple of times. ... BlackIce was able to detect it an block the probes. ...
    (comp.security.firewalls)
  • TCP_Probe_HTTP
    ... I am getting 97 or more probes from one of our know web hosting customers ... he has Charter Internet and a Router. ...
    (comp.security.firewalls)
  • Re: 56k dial up on laptop 802.11G ?
    ... >>>No NAT router is running FW software in the traditional sense. ... >> Linux firewall is not a firewall... ...
    (alt.internet.wireless)