Re: Closing Open Ports

From: Karl Levinson [x y] mvp (levinson_k_at_despammed.com)
Date: 10/15/03


Date: Wed, 15 Oct 2003 07:28:25 -0400

There's no logging, so if you're hacked, you've no idea who did it, and if
there's a problem, you've no idea what port you need to open up. There's no
simple GUI like a firewall management console to easily set up multiple
rules. There's no reporting or alerting or intrusion detection. And
dynamic protocols like FTP don't work well through such rules, unless you
open up a whole lot of ports you didn't really want to open. And, a trojan
or virus could potentially disable IPsec. And IPsec can't tell you which
executable is generating network traffic or block traffic by executable,
like many free personal firewalls can. By comparison, the XP ICF firewall
is arguably way better than IPsec rules in a number of ways.

Bottom line, IPSec is not a good firewall, especially if you're not already
a TCP/IP filtering expert and can troubleshoot setup problems without a log
of blocked packets. You can always get better functionality and more
security by going to a real firewall.

"j" <anonymous@discussions.microsoft.com> wrote in message
news:05f901c392d0$f70c09c0$a401280a@phx.gbl...
> Couldn't you use IPSec IP filter lists to block open ports
> as well?



Relevant Pages

  • Re: VPN not working when client behind another firewall
    ... The latest is that we have tested the ports and GRE ... >place a hardwarebased firewall router out in front of SBS ... This area is NAT-T over IPSec across ... >server to work when behind a NAT. ...
    (microsoft.public.windows.server.sbs)
  • Re: Dateien kopieren
    ... > IPsec Firewall alles blockiert. ... Du mußt soviele Ports öffnet, dass sich die Sinnfrage der Firewall ... IPSec-Verbindung auf den Server herstellen. ...
    (microsoft.public.de.german.windows.server.general)
  • Re: IPSec and Passive FTP
    ... The best way to go about it with IPSec is to block any ... How do you specify "high ports?" ... >The best way to deal with FTP is to use a connection tracking firewall ...
    (comp.security.firewalls)
  • Re: IPSEC
    ... > IPSEC works differently than a firewall in that a firewall will allow ... > IPSEC will not allow any inbound traffic regardless of the origin, ... > in lieu of individual rules denying traffic on specific ports. ... If deny all rule is there then ALL ports except for those specifically ...
    (comp.security.firewalls)
  • Re: Trouble accessing Outlook Web Access from behind firewall
    ... When starting the firewall I also set ... > rejected and dropped packets are logged, however I see nothing in my log ... > # Higher ports needed to accept incoming/outgoing calls ...
    (comp.security.firewalls)