Re: Port Blocking

From: Jeff Cochran (jcochran.nospam_at_naplesgov.com)
Date: 12/18/03


Date: Thu, 18 Dec 2003 22:53:43 GMT

On Thu, 18 Dec 2003 12:35:14 -0800, <lavi@icshawaii.com> wrote:

>I want to use TCP/IP filtering and block all the porst
>that i may not need to have open on my win2000 server web
>server. I am running the following on my web server.

Wrong move on two fronts. First, never block ports you don't need,
instead open only the ports you need.

Second, this is best done in your firewall and not TCP/IP filtering.

>Cold Fusion Server, Crystal Enterprise 8.5, FoxPro7, SQL
>Server 2000, and Mdaemon Pro mail server.
>
>I have 2 servers, server A and server B. Server B gets
>data from a Fox DB on server A. Server A hosts my
>website, and it also writes data into a SQL DB.
>
>Could someone please tell me which ports I need open for
>my 2 servers based on the apps and services i use? I want
>to block all except the one s i need to use. If you need
>more info, pls e-mail me at lavi@icshawaii.com.

Easiest is block everything and review the firewall logs for what's
being blocked. Also check the port list:

http://www.iana.org/assignments/port-numbers

Jeff



Relevant Pages

  • Re: Hacked?
    ... Mike Burgess http://www.mvps.org/winhelp2002/ ... >>> currently hosting the email server, DNS, as well ... Also opened ports for ssl, ... >>> more attention to the firewall logs, ...
    (microsoft.public.security)
  • Re: Whats a decent modem/router for tech savy user?
    ... It is not possible to route or deny traffic to specific ports based on the source IP address. ... But it wont route back inside the LAN - needs internal DNS server spoofing. ... Normally, this option should be Enabled, so that an Internet connection will be made automatically, whenever Internet-bound traffic is detected. ... Specifying a Default DMZ Server allows you to set up a computer or server that is available to anyone on the Internet for services that you haven't defined. ...
    (uk.telecom.broadband)
  • Re: Cannot connect to RWW from home PC
    ... That would be the address you need a DNS record for. ... You say "And in the router you need to forward to your external nic IP" ... Still can't telnet to any of your ports at your public ip address. ... Heres' the info for our server: ...
    (microsoft.public.windows.server.sbs)
  • Re: Netopia 3347NWG with Remote Desktop and Remote Web Workplace
    ... Glad you're back in business Greg! ... Ports Closed ... Despite this, Remote Web Workplace DOES WORK now, and Connect to Server ... Exchange BPA updates), ...
    (microsoft.public.windows.server.sbs)
  • Solution -> Re: SSH tunnel question.
    ... change IPS and ports around but that is not a big deal. ... telnet/ftp/rsh open on a server including on the Internet facing ports! ... I will go from the corp desktop to a hop ... through the firewall to the hop ...
    (SSH)

Loading