Re: blocking some common TCP/UDP ports

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 02/25/04


Date: Tue, 24 Feb 2004 23:20:23 GMT

You may be doing this already, but it is best to have a block all default rule for
outbound access and then add the allowed exceptions. I will leave a link or two, but
you may have better luck searching http://google.com for the associated ports such as
"Yahoo messenger ports" or try to track them down yourself by using something like
TCPView [free from SysInternals] to see what ports are used on a test computer or
view your firewall logs. --- Steve

http://www.sysinternals.com/ntw2k/source/tcpview.shtml
http://www.iss.net/security_center/advice/Exploits/Ports/
http://www.governmentsecurity.org/articles/CommonPorts.php

"Jodie" <jodie.fearon@cesjm.com> wrote in message
news:%23rg8LGx%23DHA.4012@tk2msftngp13.phx.gbl...
> I have an NT Server running firewall on my network to allow shared LAN
> access to the internet. I want to be able to prevent downloads and uploads
> EXCEPT from specified IP addresses.
>
> I would also like to block MSN Messenger and Yahoo instant messenger unless
> from specified IP addresses.
>
> I want to allow HTTP only from most IP addresses and block MSN Messenger,
> Yahoo Messenger, WinMX, Kazaa and all other common internet file sharing
> systems.
>
> My firewall allows my to do packet filtering based on protocols and their
> port numbers. Can anyone tell me what are the common port numbers for these
> applications or know where I can find that information? I now the general
> number for HTTP, FTP etc. but I do not know what port number WinMx and the
> others use.
>
> Thanks.
>
>



Relevant Pages

  • Re: Trouble accessing Outlook Web Access from behind firewall
    ... When starting the firewall I also set ... > rejected and dropped packets are logged, however I see nothing in my log ... > # Higher ports needed to accept incoming/outgoing calls ...
    (comp.security.firewalls)
  • Re: iptables configuration
    ... >> that if a 'virus/trojan' initiated a connection to the net, the firewall ... >> would not protect the LAN. ... The LAN is NATed with private IPs to one public IP. ... the ports that are used by services running on linux. ...
    (comp.os.linux.security)
  • Re: Norton Personal Firewall 2003
    ... |> First thing I would do is put the GRC test site into the Exclusions ... | ports they will not get the same result being in my blocklist, ... the firewall checks unsolicited inbound communications attempts. ...
    (comp.security.firewalls)
  • Re: What is broken:McAfeee firewall or my router ????? Urgent, ple
    ... your computer regardless of what McAfee firewall said. ... If your router is ... warned about those ports being available right away if you had any of those ...
    (microsoft.public.security)
  • Re: What is broken:McAfeee firewall or my router ????? Urgent, ple
    ... your computer regardless of what McAfee firewall said. ... If your router is ... warned about those ports being available right away if you had any of those ...
    (microsoft.public.security)