Re: TCP Port selection

From: Steven L Umbach (sumbach_at_nospam-ameritech.net)
Date: 01/29/04


Date: Thu, 29 Jan 2004 20:11:39 GMT

I don't know of a way to do that [other than for rpc]. You should consider
using a stateful packet inspection firewall with a default block all
outbound rule and then configure just the exceptions for allowed
services/applications. A rule for internet access would have to allow return
traffic from any port, but only from traffic you intiated to port 80 tcp for
instance. It is the job of the firewall to track the "state" of the
connection so that uninitiated traffic from any other port or ip address is
not allowed in. --- Steve

http://www.netscreen.com/products/firewall/security/stateful_inspection.jsp

"D Comeau" <wysiwyg08620@yahoo.com> wrote in message
news:6b1b01c3e69e$5f15c7b0$a001280a@phx.gbl...
> Can I configure W2k to utilize a specific range of ports
> (or even restrict the use of a range of ports)? We have
> configured ACL's on our routers that restrict connections
> to dest ports 3127 to 3198 in an attempt to reduce the
> affects of the MyDoom worm. However, Windows randomly
> uses ports to connect to systems. As an example, I open
> my web browser to www.microsoft.com and I use TCP port
> 3127 as my source port, the packet goes out to
> www.microsoft.com port 80, but the return packet does not
> get through.



Relevant Pages

  • Re: D-Link DI-804HV Router Firewall SPI Function
    ... > Charles wrote: ... A firewall that uses Stateful Packet Inspection ... > closed port, your router will transmit back an RST packet saying "no, you ... > closed instead of stealth, it's not the end of the world. ...
    (comp.security.firewalls)
  • Re: D-Link DI-804HV Router Firewall SPI Function
    ... A firewall that uses Stateful Packet Inspection ... > will show a 'BLOCKED' result for this port". ... Stealthed ports are when your router ... closed instead of stealth, it's not the end of the world. ...
    (comp.security.firewalls)
  • Re: D-Link DI-804HV Router Firewall SPI Function
    ... > of my home computer. ... A firewall that uses Stateful Packet Inspection ... "This port has not responded to any of our probes. ... you need to read more about computer security. ...
    (comp.security.firewalls)
  • D-Link DI-804HV Router Firewall SPI Function
    ... I purchased a D-Link DI-804HV router in order to increase the security ... the Sygate Online Services website it found the "service" SOURCE PORT ... A firewall that uses Stateful Packet Inspection ... Is this a router hardware problem or do I ...
    (comp.security.firewalls)