On 5 Apr 2000, Rhett R. Rodewald wrote:

> Boffo mistake -- Ash's mods do work if applied correctly -- I thought he was
> using the "/" to seperate S-Port and D-Port, didn't realize that was the
> syntax for specifing a range.  (Noticed that after re-reading the docs...wow)
> 
> Anyway, is there a way to make this work without opening up _all_ the ports
> from 5000 to 65555???

If the other system may use any port from 5000-65535, then no, but:

1) If no systems on your LAN have services on ports in that range, it
doesn't matter.

2) You can set up the firewall entries to allow the unrestricted access
only for the DNS servers' IP addresses.  This isn't bulletproof, but it at
least makes it more difficult for an attacker.  Of course there's no way
to do this with dynamic DNS IPs.

                                        Fred Wright

-- 

To unsubscribe send "unsubscribe miami-talk-ml" to
"[EMAIL PROTECTED]". For help on list commands send "help" to
"[EMAIL PROTECTED]".


Reply via email to