Re: Possible firewall problem?

From: Copelandia Cyanescens (synesthesia_at_ix02x67invalid.net)
Date: 08/30/04


Date: Sun, 29 Aug 2004 23:30:14 +0000

Leythos wrote...

>> I'm noticing an occasional entry in my firewall logs and I'm not sure if
>> it's a problem or not. I'm seeing a 40 byte TCP packet going outbound
>> from my local port 25 to a remote port (seems to change, but last one
>> was 4043). The remote IP address doesn't look familiar. Seems to be
>> just a random address somewhere. In the info column of the logs, it
>> just says TCP flags: RST ACK.

[...]

> Unless you have your email client open and running on your desktop, or a
> email status app (like a tray icon) running, there is no reason for your
> system to do an outbound port 25 connection.
>
> Outbound port 25 is representative of something sending email outbound
> to somewhere.

That's backwards. In general, email clients send mail using random ports
in the "thousand-something" range TO port 25. Traffic going out on port
25 would indicate a response to *incoming* mail. The above traffic would
indicate a "not listening" reply to someone attempting to send mail to
the poster's (probably non-existent) email daemon/host/server...
whatever you want to call it.

-- 
Peace is only better than war when it's not hell too. War 
being hell makes sense.
                                          -- Walker Percy


Relevant Pages

  • Re: Will Exchange using nonstandard port cause problems with Sharepoint?
    ... about changing the std outbound port of Exchange. ... 'SmallBusiness SMTP Connector'. ... Next, click on the Advanced tab, then Outbound Security,, then Basic ...
    (microsoft.public.windows.server.sbs)
  • RE: Unable to print on ports 9100/515
    ... Is the protocol definition for outbound on port 9100 and 515 actually trying ... > the detailed steps to publish a TCP/IP network printer through ISA, ... > 306071 How to Publish a TCP/IP Printer Behind ISA Server ...
    (microsoft.public.windows.server.sbs)
  • Re: Outbound ports
    ... Destination Port 80 outbound ... I would never allow more than port ... >resource need) (or inbound for the DMZ). ... arguing that you meant "outbound from the WAN to the DMZ"? ...
    (comp.security.firewalls)
  • Re: [Newbie alert!] Is the Linksys BEFSX41 hardware Firewall/router a "real" firewall?
    ... there is very little that a real firewall appliance will ... ALL inbound and outbound traffic in real time - a simple KVM switch will ... outbound SMTP then it can spam all it wants. ... Private Ports in some versions - where you can list port ranges to block ...
    (comp.security.firewalls)
  • Re: IPSec policie is not working like it should
    ... outbound have to be enabled. ... > I'm not sure how you can force all your traffic to go out a single port. ... > Almost all of your applications are going to be given dynamic outbound ... Outgoing mail is certified Virus Free. ...
    (microsoft.public.windows.server.networking)