Extracted from the mind of Fred Wright;
>On 5 Apr 2000, Rhett R. Rodewald wrote:
>> Boffo mistake -- Ash's mods do work if applied correctly -- I thought he
>> was using the "/" to seperate S-Port and D-Port, didn't realize that was
>> the syntax for specifing a range. (Noticed that after re-reading the
>> docs...wow)
>>
>> Anyway, is there a way to make this work without opening up _all_ the ports
>> from 5000 to 65555???
>If the other system may use any port from 5000-65535, then no, but:
>1) If no systems on your LAN have services on ports in that range, it
>doesn't matter.
>2) You can set up the firewall entries to allow the unrestricted access
>only for the DNS servers' IP addresses. This isn't bulletproof, but it at
>least makes it more difficult for an attacker. Of course there's no way
>to do this with dynamic DNS IPs.
> Fred Wright
I'd like to follow up on the last, Fred. My DNSs are known, 208.xxx.yyy.zzz
and something else I can't even remember the first number of. I assume that
htey are by definition static? So could I arrange to have Miami's firewall to
pass only packets from the DNSs to ports 48000/65535?
A look at the firewall settings suggests that one could also set up the
firewall to allow outside access to say port 5000 of the machine with IP
number 192.168.1.5, and only that port on that machine. Sending a packet to
port 5000 of 192.168.1.6 or 192.168.1.4 would not be permitted.
I don't suppose that many people understand all that a firewall can and can't
do. I know that I don't.
-ash
for assistance dial MYCROFTXXX
--
To unsubscribe send "unsubscribe miami-talk-ml" to
"[EMAIL PROTECTED]". For help on list commands send "help" to
"[EMAIL PROTECTED]".