Re: TCP/IP Filtering - can't browse Internet

From: Q (Q_at_nospam.net)
Date: 01/29/03


Date: Wed, 29 Jan 2003 11:25:21 -0500


"Sphinx" <DIESPAMDIEsphinx@attbi.com> wrote in message
news:tJIZ9.75486$Ve4.6238@sccrnsc03...
> Hello, folks.
>
> I just enabled TCP/IP filtering on my W2k Server box. I allowed the
> following protocols on both TCP and UDP: ports 20, 21, 53, 80. I can
connect
> to the server's FTP contents, but I cannot browse the Internet from the
> server.
>
> Can anyone tell me why that is?
>
> Thanks!
>
>
Normally you will need to:
a) allow incoming TCP to ports greater than 1023
b) deny SYN packets to ports greater than 1023
In w2k filtering this is expressed as "TCP established" if I remember
correctly.

To allow DNS resolution, another rule must be used: Allow UDP incoming from
DNS IP addresses srcport 53 to ports greater than 1023.

This should allow you to browse From the w2k box.

HTH,

Q.



Relevant Pages

  • Re: TCP/IP Filtering - cant browse Internet
    ... > I just enabled TCP/IP filtering on my W2k Server box. ... allow incoming TCP to ports greater than 1023 ... To allow DNS resolution, another rule must be used: ...
    (microsoft.public.win2000.security)
  • Re: Whats a decent modem/router for tech savy user?
    ... It is not possible to route or deny traffic to specific ports based on the source IP address. ... But it wont route back inside the LAN - needs internal DNS server spoofing. ... Normally, this option should be Enabled, so that an Internet connection will be made automatically, whenever Internet-bound traffic is detected. ... Specifying a Default DMZ Server allows you to set up a computer or server that is available to anyone on the Internet for services that you haven't defined. ...
    (uk.telecom.broadband)
  • Re: Cannot connect to RWW from home PC
    ... That would be the address you need a DNS record for. ... You say "And in the router you need to forward to your external nic IP" ... Still can't telnet to any of your ports at your public ip address. ... Heres' the info for our server: ...
    (microsoft.public.windows.server.sbs)
  • Re: Netopia 3347NWG with Remote Desktop and Remote Web Workplace
    ... Glad you're back in business Greg! ... Ports Closed ... Despite this, Remote Web Workplace DOES WORK now, and Connect to Server ... Exchange BPA updates), ...
    (microsoft.public.windows.server.sbs)
  • Solution -> Re: SSH tunnel question.
    ... change IPS and ports around but that is not a big deal. ... telnet/ftp/rsh open on a server including on the Internet facing ports! ... I will go from the corp desktop to a hop ... through the firewall to the hop ...
    (SSH)

Quantcast