Re: Probes on Port 135 and 445 continue

From: Barry Margolin (barmar_at_alum.mit.edu)
Date: 10/15/04


Date: Thu, 14 Oct 2004 19:55:16 -0400

In article <MPG.1bd7aeecdee6cc0d98985f@news-server.columbus.rr.com>,
 Leythos <void@nowhere.org> wrote:

> In article <barmar-1733B7.20583013102004@comcast.dca.giganews.com>,
> barmar@alum.mit.edu says...
> > In article <MPG.1bd71044b7cc3152989857@news-server.columbus.rr.com>,
> > Leythos <void@nowhere.org> wrote:
> >
> > > The above is what makes a firewall device in my book, all the others are
> > > just NAT boxes.
> >
> > To me, the distinction you described is between a "basic firewall" and a
> > "full-featured, powerful firewall".
>
> Barry, I don't see the difference. The NAT box has no idea what SMTP is,
> no idea what HTTP is, all it knows is ports, it doesn't care what runs

A basic firewall doesn't have to know about application protocols. If
it allows you to block port 25 and allow port 80, it's more than just a
NAT box. No, it won't do virus checking on that traffic, but that's an
"advanced" firewall feature, not a basic one.

What were the things that we called firewalls 15 years ago, long before
all this application data scanning became popular? In those days we
just set up a bastion host, and configured the Internet router to only
allow incoming traffic to that one machine. But there were no virus
scanners yet.

> over those ports. The firewall understands SMTP and doesn't care what
> port it runs on, same for the other services.

I very much doubt that. Someone has to tell it what application
protocols are using which ports. When it sees traffic on port 80, it
knows to scan it for HTTP protocol messages; when it sees traffic on
port 25, it knows that it should look for SMTP messages. On some
arbitrary port, there's no way for it to know what application-specific
scanning it should perform.

-- 
Barry Margolin, barmar@alum.mit.edu
Arlington, MA
*** PLEASE post questions in newsgroups, not directly to me ***


Relevant Pages

  • Re: SBS 2003 and Outlook RPC over HTTP issues
    ... , but some of my clients do not want users to ... definitely closed now cause when I open it up http: ... the article is incorrect in stating that port 80 is needed. ... that port 443 and port 80 must be open to use RPC over HTTP. ...
    (microsoft.public.windows.server.sbs)
  • Re: Public Website on SBS 2003
    ... hosting and PROTECTING a website is specialist field and ... As leythos says you need to open HTTP port to the www. ... network settings are on servers internet connections. ...
    (microsoft.public.windows.server.sbs)
  • Re: SBS 2003 and Outlook RPC over HTTP issues
    ... Look in IIS at your Exchweb, Exadmin, exchange-oma, and RPC sites' directory ... Why is it called RPC over HTTP if HTTP is not really needed to be ... As pointed out by others, port 80 does NOT need to be open, and yes, it ... I have about 20 of these SBS machines at other locations and have ...
    (microsoft.public.windows.server.sbs)
  • Re: Help understanding error message
    ... Saravana Kumar [MVP - BizTalk Server] ... Receive port is reported to be HTTP but I don't any see HTTP packets in ... Maybe you set up a two-way send port being directed to a one-way ... Details:"Unable to read data from the transport connection: The ...
    (microsoft.public.biztalk.general)
  • Re: [fw-wiz] tunnel vs open a hole
    ... It does depend on what protocols you are passing through the port or the ... If the protocol is pure HTTP, ... If the protocol is new whizbang multi-media binary with no RFC or complete ... or tunnel over currently open port 80? ...
    (Firewall-Wizards)