Re: open port numbers behind the firewall



Steve <javacc2@xxxxxxxxx> wrote:
Do we need to open the same port 1521 on websphere server too?

Unlikely.

We need to open the port that the database server listens from the
websphere server's request. But what port the websphere listens on the
response from the database server?

That's irrelevant. The response from the database server will take the
same route as the request, only in the opposite direction. If the
firewall is stateful (which it should be), you don't need to do anything
other than allow requests to the database server's port.

I think the similar analogy is like the web browser. When we go to
http://www.google.com, the google server listens on port 80 for the
requests from the web browser. how about the data send back from the
web server to the web browser, what port web browser listens?

Web browsers don't listen on any port. It's the same as described above.
The response goes back through the already established connection.

cu
59cobalt
--
"If a software developer ever believes a rootkit is a necessary part of
their architecture they should go back and re-architect their solution."
--Mark Russinovich
.



Relevant Pages

  • Malicious use of grc.com
    ... ShieldsUpis an application developed by Steve Gibson of Gibson ... Research Corporation that allows a web user to request a remote port scan ... ShieldsUp happily scans the other box while returning the result set into ...
    (NT-Bugtraq)
  • Malicious use of grc.com
    ... ShieldsUpis an application developed by Steve Gibson of Gibson ... Research Corporation that allows a web user to request a remote port scan ... ShieldsUp happily scans the other box while returning the result set into ...
    (Incidents)
  • Malicious use of grc.com
    ... ShieldsUpis an application developed by Steve Gibson of Gibson ... Research Corporation that allows a web user to request a remote port scan ... ShieldsUp happily scans the other box while returning the result set into ...
    (Vuln-Dev)
  • RE: NT Compromise
    ... TCP port 6667 and 6668 are used for IRC. ... to this it seems that your server might have connection to one of IRC ... Subject: NT Compromise ... has timed out a request to STEELSRV. ...
    (Incidents)
  • Malicious use of grc.com
    ... ShieldsUpis an application developed by Steve Gibson of Gibson ... Research Corporation that allows a web user to request a remote port scan ... ShieldsUp happily scans the other box while returning the result set into ...
    (Bugtraq)