> I'm really sorry that I have to ask that stupid question....

  no such thing as a stupid question.
 
 
> But how do YOU deal with TCP ports over 1024(dynamic ones)?

  disallow access to them unless they are part of an established
  connection, so if they are being used, then someone inside your security
  perimeter must have opened a connection on a privileged port, which
  connection then required the use of a high port.

  It goes back to having to trust the folks on the inside and allowing 
  functionality.

Hope that helps


===================================================================
Larry Chin {[EMAIL PROTECTED]}      Technical Specialist - ISC
Sprint Canada                     2550 Victoria Park Avenue
Phone: 416.496.1644 ext. 4693     Suite 200, North York, Ontario
Fax:   416.498.3507               M2J 5E6
===================================================================
  

-
[To unsubscribe, send mail to [EMAIL PROTECTED] with
"unsubscribe firewalls" in the body of the message.]

Reply via email to