On Feb 8, 2005, at 10:57 AM, jake wrote:

You should block everything that isn't used.
sounds right.

bruce, this is the list of ports to bar traffic from that i found online:
20, 25, 111, 135, 137, 139, 445, 515, 1080, 1433, 1434, 3128, 3306, 6000,
8080.


obviously there are loads of others...

i'm wondering if there is a way to do it the other way round, ie close
everything except 80 and 21?

I don't know anything about your model firewall. RTM. There should be a way to do it. It would be a pretty incompetent firewall otherwise.



Use port 22 for SSH (and stop using FTP, use sftp instead, or tunnel
ftp over ssh), turn on port 80, and see what breaks.
interested by sftp - will i still be able to get my users to use transmit to
login and download/upload.



Yes transmit does SFTP iirc, or they can use Fugu, which is free.

--
Bruce Johnson
University of Arizona
College of Phar macy
Information Technology Group

Institutions do not have opinions, merely customs


-- G-List is sponsored by <http://lowendmac.com/> and...

Small Dog Electronics    http://www.smalldog.com | Refurbished Drives |
-- We have Apple Refurbished Monitors in stock!  |  & CDRWs on Sale!  |

     Support Low End Mac <http://lowendmac.com/lists/support.html>

G-List list info:       <http://lowendmac.com/lists/g-list.shtml>
 --> AOL users, remove "mailto:";
Send list messages to:  <mailto:[email protected]>
To unsubscribe, email:  <mailto:[EMAIL PROTECTED]>
For digest mode, email: <mailto:[EMAIL PROTECTED]>
Subscription questions: <mailto:[EMAIL PROTECTED]>
Archive: <http://www.mail-archive.com/g-list%40mail.maclaunch.com/>

iPod Accessories for Less
at 1-800-iPOD.COM
Fast Delivery, Low Price, Good Deal
www.1800ipod.com

Reply via email to