Re: HTTP!!!! Does it use any UDP ports?

From: karl [x y] (jamescagney90210@excite.com)
Date: 08/08/02


From: "karl [x y]" <jamescagney90210@excite.com>
Date: Thu, 8 Aug 2002 08:15:41 -0400


"Keith W. McCammon" <km@km.com> wrote in message
news:elhZVskPCHA.1996@tkmsftngp12...

> Q: How does it do that?
> A: DNS.
>
> Q: What ports does DNS require?
> A: Destination port 53/UDP.

... and TCP 53 if the DNS request cannot be answered in a single UDP packet.

If you're using a firewall to do this blocking, you always want to check the
firewall log immediately after a failed access, to see what port, if any, is
being blocked, and to see what rule you need to add or modify to open things
up. This logging is also essential IMHO since you'll never know if a hacker
is trying to get into your system or has gotten into your system, or who the
hacker is, without logging. If you're using a low end NAT router such as
Linksys or Netgear for this, you may need to set up Syslog and download a
syslog client such as the free one from www.kiwi-enterprises.com to capture
the logging.

The packet filtering that comes with Windows 2000 IPsec has no such logging,
which is why I would always recommend forgetting IPsec and using a third
party packet filtering tool such as the Sygate firewall [free for
non-commercial use] instead.



Relevant Pages

  • Website setup questions.
    ... Create firewall rule to direct HTTP port 80 to the SBS External NIC ... Create firewall rule to point DNS port 53 to the SBS External NIC ... NICS to get this request to not timeout or be refused. ...
    (microsoft.public.windows.server.sbs)
  • Re: Bind as cache DNS and firewall
    ... I'm using Bind as a cache DNS for a public network. ... As it's UDP I think of UDP queries going from my cache server to other DNS server, and I catch their UDP responses in the firewall. ... So I should open my firewall for UDP on port 53 for all the world? ...
    (comp.protocols.dns.bind)
  • RE: strange traffic on UDP port 53
    ... Replies to DNS queries should be coming FROM port 53, ... > found a similar problem with packets being stopped by our firewall. ... The destination IP is our mail server (not ...
    (Incidents)
  • Re: Suspecious DNS traffic
    ... down an answer to a question, it would sent the remote authoritative DNS ... Then BIND randomised this 16 bit query ID which made it more difficult. ... We asked and received answers all on port 53. ... Your Firewall could be configured to allow BIND to do this. ...
    (comp.protocols.dns.bind)
  • Re: port 53, please help!
    ... >> port 53 as blocked. ... >to folks with a Win98 connected thru a firewall to internet. ... find out the IP addresses of all your DNS servers. ...
    (comp.security.firewalls)