Re: Possible firewall problem?

From: Lars M. Hansen (badnews_at_hansenonline.net)
Date: 08/30/04


Date: Sun, 29 Aug 2004 18:14:31 -0400

On Sun, 29 Aug 2004 13:06:11 -0700, Kerodo spoketh

>
>Ok, thanks Lars.. But doesn't it mean then that a packet is getting
>thru the firewall rules somehow and getting in? What I'm concerned
>about is that there is a "hole" in the firewall..

Even if it was not the firewall itself that were sending the reply
packet but rather the OS, it really doesn't matter a whole lot. If you
don't have anything running on port 25, then no external (or internal
for that matter) clients can connect to this port.

I agree that it is somewhat odd that the firewall logs the outgoing
"rst" packet rather than simply logging the connection attempt from the
external source ... and, most desktop firewalls actually "stealths" port
rather than sending out rst's. But I still don't think it's anything to
lose sleep over.

Lars M. Hansen
http://www.hansenonline.net
(replace 'badnews' with 'news' in e-mail address)



Relevant Pages

  • RE: Strange replies on closed port
    ... port should be a RST - not dropping the packet. ... receiving an UDP datagram to a non 'listening' port. ... that message isn't generated by the end host, ... Connecting to a closed Port w/o Firewall: ...
    (Pen-Test)
  • Re: Basic NAT / Firewall Question
    ... There are two basic types of NAT (Network Address Translation) which you ... NAPT simply maps port numbers to a given address. ... Your firewall will make a note from where the connection was ... with its own address and then sends this "new" packet out on its local ...
    (Security-Basics)
  • Re: FTP Window of opportunity?
    ... Your computer sent a SYN packet... ... a SYN/ACK back, ... > well as blocked by the firewall. ... > When I scan with ISS, the FTP port shows up. ...
    (Pen-Test)
  • Re: Firewalls: whats the use?
    ... >> control the types of ICMP message sent and received. ... Do I really need to implement a firewall just to prevent ICMP? ... packet to crash the OS. ... especially in cases where the packet was destined to a port where no ...
    (comp.os.linux.security)
  • Re: Kerio PFW 2.14 - Safe?
    ... >> down user interface. ... Then consider the fact that most packet ... If Kerio 'X' says it's stateful it most ... >> way to know for sure would be to stand between the firewall and the ...
    (comp.security.firewalls)