Re: TCP/IP Filtering

From: Toni Lassila (mpao@mc-europe.com)
Date: 10/22/02


From: mpao@mc-europe.com (Toni Lassila)
Date: 22 Oct 2002 01:54:55 -0700


"dave kleiman" <dave@netmedic.net> wrote in message news:<9f9001c27969$53e70050$35ef2ecf@TKMSFTNGXA11>...
> I have discovered (not sure if that is the right word) an
> interesting thing in reference to using TCP/IP Filtering
> on a W2000 client.
>
> I was attempting to setup my home system using the built
> in TCP/IP Filtering. I Allowed only Ports 25 Mail, 53
> DNS, 67&68 DHCP, and 80&443 Internet.

Looks like you're using TCP instead of UDP. See:

<http://groups.google.com/groups?selm=b11796dd.0209032255.46f2ef66%40posting.google.com>
 
> Well I found out that DNS returns to a client on a port
> >1024. So I picked the first 3 unassigned above 1024
> ports. Well that worked until the third time I opened a
> web browser (no DNS resolution). I looked with NETSTAT -na
> and found that it was now trying to use a port higher than
> the 3 I selected. I opened up 10 more >1024 ports. Well
> the worked till about the 7th time I opened the web
> browser.

This should not be necessary. Any stateful firewall is assumed
to automatically keep track of opened TCP-connections, and allow
incoming responses to dynamic ports when appropriate.

There should rarely be a reason for adding "allow" rules for
dynamic ports. DNS queries are definately not such a reason.



Relevant Pages

  • RE: TCP/IP Filtering problem on W2KAS
    ... The problem is that if you are listing ports that are 'allowed' and you ... don't list every dynamic port used by a client to access the DNS ... "Using IPSec to Lock Down a Server": ... I find using the IPSec filters MUCH more useful then the TCP/IP Filtering. ...
    (Focus-Microsoft)
  • Re: Client need to key in credential to access shared folder
    ... We have even try to open all services bet the two domain to check it is the firewall that blocking the ports but the problem still persist. ... The ports bet Client and DC have already been open up. ... >> All my client and server have already specified their own internal DNS ... > join to a existing forest which has only domain B. ...
    (microsoft.public.win2000.active_directory)
  • Re: TCP/IP filtering and opening DNS
    ... > I am having some problems with TCP/IP filtering and DNS with my ... > know its something with DNS. ... You also need to open ports above 1024 for outgoing connections. ...
    (microsoft.public.win2000.dns)
  • Re: Client need to key in credential to access shared folder
    ... the firewall that blocking the ports but the problem still persist. ... > The actual problem we have is when client at domain A connect to client at ... How can you go to a client A machine and trace the DNS ... >>> All my client and server have already specified their own internal DNS ...
    (microsoft.public.win2000.active_directory)
  • Re: Getting Active Directory replication working over firewalls & nat
    ... -Make sure that your Dns estructure is correctly configured. ... -Make sure that you've the need FW Ports open (check the links already ... Direct a Distributed File System client to the server that is ...
    (microsoft.public.windows.server.active_directory)