>I was also working under this assumption, any allow "ANY" outgoing
>traffic. So, basically you're saying I can block all outgoing traffic with
>no ill effects to web/email/etc?
>
>Is there a reason to do this? Nobody actually sits at the server and surfs
>the internet or anything.
If you do block outgoing traffic, you'll need to [1] Make sure that any
legitimate outgoing connections are allowed (IE outgoing connections to the
SMTP port on remote mailservers and outgoing DNS requests needed for mail
delivery), and [2] That your firewall (or router) doesn't require you do
something special (a special line to all established TCP/IP connections, or
allowing outgoing traffic on all ports >1024) as per the other E-mails in
this thread.
The reason why you might want to do this is to help minimize problems if
the server is compromised. For example, blocking all outgoing traffic
except SMTP/DNS traffic would mean that if the server was compromised, a
trojan horse on the server would have to communicate via SMTP or DNS ports
if sending outgoing traffic, making the hacker's job more difficult.
-Scott
---
Declude: Anti-virus, Anti-spam and Anti-hijacking solutions for
IMail. http://www.declude.com
---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
Please visit http://www.ipswitch.com/support/mailing-lists.html
to be removed from this list.
An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Please visit the Knowledge Base for answers to frequently asked
questions: http://www.ipswitch.com/support/IMail/