Re: TCP/IP Filtering in Windows 2000?

From: Alex Homer (alex@stonebroom.com)
Date: 01/26/03


From: "Alex Homer" <alex@stonebroom.com>
Date: Sun, 26 Jan 2003 10:02:12 -0000

I already have TCP filtering on, with "Allow only" for TCP ports set and the
ports I need to use open (including 53). Browsing, ping and nslookup work
fine when UDP Ports is set to "Allow all". If I set UDP Ports to "Allow
only", and then add the same ports as TCP, plus all the others that several
people have suggested at various times (69, 139, 520, etc.) then browsing
produces "Not found" and ping produces "Server not found". After several
attempts over a long period, the results are always as above. It can only be
that I need to open another port. But which one?

Does anyone actually have this set up and working? I've tried the
combinations of ports shown on the very few Web sites that list the ports
you need. I suspect there is a bug or other problem in the Windows 2000
implementation, as I have never seen had a reply from anyone who actually
has a working setup that does allow browsing.

"x y" <levinson_k@excite.com> wrote in message
news:eqyXO8JxCHA.2184@TK2MSFTNGP09...
> Did you also enable TCP 53 as well? [probably a good idea] What happens
> when you try to use NSLOOKUP [example, NSLOOKUP www.yahoo.com ] to see if
> the problem is name resolution or not?
>
> I've heard that both TCP 1433 and 1434 should be blocked in both
directions,
> not just for this worm but for others. [Of course, blocking everything
> except that which is needed is even better.]
>
> You might also try IPSec filtering instead of TCP/IP filtering, since this
> can block outbound packets as well as inbound. Better yet, use a real
> firewall [neither of these features is a firewall]. www.sygate.com is
free,
> as are others. Firewalls give you logging, which is essential to
> troubleshoot problems like this.
>
> http://securityadmin.info/faq.htm#ipsec
>
> Also, internet is very slow or sometimes does not respond at all due to
> worms using up bandwidth. Any chance that could be your problem?
>
>
> "Alex Homer" <alex@stonebroom.com> wrote in message
> news:#ZOpeuJxCHA.2916@TK2MSFTNGP09...
> > It looks the suggestion is to block post 1434 to protect against the
> latest
> > DDoS attack. Anyone succeeded in setting up Windows 2000 TCP/IP
Filtering
> on
> > UDP packets, while still allowing browsing from this machine? Common
sense
> > says only port 53 needs to be open, but despite trying loads of other
> > "suggested" ports as well I still can't ping or browse from the machine
> with
> > UDP filtering enabled.
> >
> >
>
>



Relevant Pages

  • Re: TCP/IP Filtering in Windows 2000?
    ... maybe TCP 53]. ... hostname or PING -a hostname] and then trying to ping the IP address after ... So NSLOOKUP doesn't work when filtering is enabled? ... > ports I need to use open. ...
    (microsoft.public.security)
  • RE: IM Programs
    ... want to block these ports. ... you don't need an explicit deny for the other ports. ... Access-list 101 deny any tcp any any eq 5000 ... >Now, when applying these to your firewall, make sure the number ...
    (Security-Basics)
  • Re: What should I block out with my new firewall software?
    ... >> block out that I don't use or need, like UDP or TCP. ... >> activity or attempts from outside hackers to penetrate these ports. ... never stop svchost from comunnicating on the Internet. ... > Web updates, as far as I know, are downloaded the same way that ...
    (comp.security.firewalls)
  • Re: Fingerprinting Windows O/S based on ports open?
    ... finger printing by open default ports is not always ... OS fingerprinting is not as plain and claer cut as it was perhaps a few ... settings in tcp packets. ... >> Looking for a better way to manage your IP security? ...
    (Pen-Test)
  • Re: NFS inconsistent behaviour
    ... of tcp connections in TIME_WAIT state. ... Why there are so many connections in waiting state? ... and remote port so the ports stay in use for a few minutes. ... I ran out of privileged ports due to treemounting on /net from about 50 ...
    (Linux-Kernel)

Loading