Re: What remote ports should I allow for IE ?

From: Don Kelloway (dkelloway_at_commodon.com)
Date: 09/30/04


Date: Thu, 30 Sep 2004 00:31:41 GMT


"Brendan DJ Murphy" <brendan@cpac.REMOVE.org.uk> wrote in message
news:cjeega$hid$1$8300dec7@news.demon.co.uk...
> Whats the best way to configure a firewall for Internet Browsing?
>
> My Kerio rule is set to allow the following:
>
> Protocol TCP(Out)
> Local Port: Any
> Remote address: Any
> Remote Port: Any
> Application: c:\.....\iexplore.exe
>
> In other words, Internet Explorer is allowed to talk to anything it likes
> on any port.
>
> Again, similar to an earlier post, how can I tighten this down. It
> looks too "open" for my liking.
>
> I could add a list of remote ports
> eg: 80, 8080, 443(for secure https) etc
>
> What is the recommended list of remote ports to allow for IE?
>

At a minimum you will need to allow TCP ports 80 and 443 outbound. These
two ports will provide the ability to visit the websites of a high majority,
if not all companies which offer an Internet presence. For websites which
are being hosted on a port other than the standard TCP port 80 you will
probably want to add ports 8000, 8080 and 9000 which are the most common
secondary webserver ports.

-- 
Best regards, from Don Kelloway of Commodon Communications
Visit http://www.commodon.com to learn about the "Threats to Your Security 
on the Internet". 


Relevant Pages

  • Re: Port forwarding to a client for VOIP
    ... the ports aren't doing anything are going anywhere. ... Instant Messaging with ISA Server ... Firewall client can handle complex protocols without an application filter. ... Microsoft Internet Security & Acceleration Server: ...
    (microsoft.public.isa.configuration)
  • [VulnWatch] 3Com OfficeConnect Remote 812 ADSL router exposes internal LAN computers ports during ou
    ... ports during outbound and inbound TCP and UDP sessions. ... The 3Com 812 is a widely-deployed router, found in many ISPs ADSL lines. ... for internet access. ...
    (VulnWatch)
  • Re: What should I block out with my new firewall software?
    ... > block out that I don't use or need, like UDP or TCP. ... TCP/UDP on ports 135-139 and 445 are file sharing for networking. ... No one else, especially not internet IP ...
    (comp.security.firewalls)
  • RE: Port Forwarding XP Client
    ... 59101 and 6320 from the XP client to the internet. ... First could you tell me what the three ports are in aid of? ... from client to the internet. ... SBS Server on the router. ...
    (microsoft.public.windows.server.sbs)
  • Re: Tool to find hidden web proxy server
    ... policy for Internet access says it is through IP ... > default ports and distributed the internet access to their friends. ... - analyse the outgoing HTTP traffic through the firewall from those IP ... This will allow you to determine which servers ...
    (Pen-Test)