>However, the
>original post said "...My idea is to only allow traffic on ports 25
>inbound/outbound..." I read this as wanting to filter traffic both ways.
Yes. But, all a firewall needs for you to tell it in this case is "Allow
incoming traffic on port 25" and "Allow outgoing traffic on port 25". It
should be able to figure out the behind-the-scenes stuff. Any firewall
that requires you to tell it about ports >1024 (unless you have a specific
need for them, such as to access port 8383 for web messaging) is a dumb
firewall.
>But this does not work, and as you say,
>essentially denies all inbound and outbound traffic. This, though, is not
>really a flaw in the equipment, but a flaw in router setup.
Well, yes and no. In this case, it's a flaw in the router setup, because
the manual says "You need to take this unnecessary step in order for the
firewall to work", and you didn't.
But, the problem really lies in the router itself, which should know that
if 192.168.113.111 sends a packet to port 25 on the server (from port 1086
on the client), then the server should be able to send a packet to
192.168.113.11 port 1086, no matter what outgoing restrictions were made.
>Again, this is not a requirement, but if trying to go for maximum security
>by filtering both incoming and outgoing traffic, this is a VERY EASY config
>mistake to make. :-)
... a VERY EASY config mistake to make if you use a dumb firewall.
There's no problem having the firewall block incoming and outgoing
packets. But if it doesn't allow outgoing packets on connections that were
originated from a remote source, the firewall isn't smart (read: I hope you
got a discount for doing the work the firewall should be doing).
Note that this most likely introduces a new security flaw. You are trying
to block outgoing access to all ports aside from port 25, but in reality
the firewall will allow outgoing packets to port 25 and any
port >1024. For example, that would let someone on the mailserver access
most trojan horses running on other computers. So I hope you got a
*really* good discount on that firewall (despite the nice brand name).
-Scott
---
Declude: Anti-virus, Anti-spam and Anti-hijacking solutions for
IMail. http://www.declude.com
---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
Please visit http://www.ipswitch.com/support/mailing-lists.html
to be removed from this list.
An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Please visit the Knowledge Base for answers to frequently asked
questions: http://www.ipswitch.com/support/IMail/