Re: Firewall & Port Questions

From: Jean-Francois Messier (jfmessier_at_gmail.com)
Date: 11/11/04


Date: Thu, 11 Nov 2004 14:47:02 -0500

stephane nasdrovisky wrote:
> Jason Turner wrote:
>
>> What ports should I NOT block that would still allow web browsing?
>
>
> If web = http:
>
> It depends! you may need tcp port 80 (some web servers do not use the
> assigned port 80, which mean you may have to allow ... any port if you
> want to surf test/non standard servers) and udp+tcp port 53 (probably
> only to your isp's dns server, for name resolution) if you surf directly
> (no proxy).
> If you're using a proxy, you'll need to allow the proxy port (could be
> tcp 8080) to your provider's proxy.
>
> These are outbound traffic, make sure you also allow back traffic (from
> the servers to you)

My view on this always has been to block all non-standard ports, and
open when required AND JUSTIFIED. Depends on your business rules and
politics. You could also have an internal cache DNS running on a cheap
Linux box and allow ONLY THIS BOX to use 53/udp. Some firewalls also can
act as a cache DNS.

JF



Relevant Pages

  • Re: Connecting to Linux machine remotely
    ... The way to connect to a machine from a remote location is via ssh. ... want to connect from which queries the dns server of my ISP every 5 min ... ]> need you can forward tcp ports through ssh. ...
    (comp.os.linux.networking)
  • Re: Issue with port blocking on public DNS server
    ... I am talking about the "Destination Ports" in the "Responses to local DNS ... names (other then the domain names in my own DNS server) on the servers. ... Filtering outbound requests on port 53 FROM the DNS to the Internet ...
    (microsoft.public.windows.server.dns)
  • Re: ZONe transfer
    ... > tell my w2k DNS to pull from the ISPs DNS servers zone?? ... It's a "zone transfer" so yes, you have to create the Zone internally ... on your DNS server with the SAME NAME and give it a "master" ... Ports for DNS must be open, ...
    (microsoft.public.win2000.dns)
  • Re: dns server behind a firewall?
    ... I only have one public address, and there was no firewall before. ... No additional changes on my w2k dns console? ... > (DNS server) address on ports 53. ...
    (microsoft.public.windows.server.dns)
  • Re: Cannot access internal website - 502 proxy error
    ... If ISA2k can't resolve the name, it will either forward the request to your ISP's DNS server or fail the lookup. ... Set up ISA2k4 so that it can resolve your domain DNS requests through your internal DNS server. ... NIC of ISA 2k4) and I config proxy on their IE. ...
    (microsoft.public.isa)