>> Anyway, is there a way to make this work without opening up _all_ the ports
>> from 5000 to 65555???

>If the other system may use any port from 5000-65535, then no, but:
>1) If no systems on your LAN have services on ports in that range, it
>doesn't matter.

OK, I know this is a wide open, leading question, but to the best of anyone's
knowledge, do any (important) services use ports above 5000?  Is Windows (or
any other OS) known to be vulnerable to probing in this range?


>2) You can set up the firewall entries to allow the unrestricted access
>only for the DNS servers' IP addresses.  This isn't bulletproof, but it at
>least makes it more difficult for an attacker.  Of course there's no way
>to do this with dynamic DNS IPs.

I assume this requires a seperate entry for each DNS server?  Obviously, I
don't want to open up too wide of a range of addresses, or I wouldn't bother
in the first place.


>                                       Fred Wright

Thanks Fred and Ash for all the insight.


-----------------------------------------------------------------------------
                            Rhett R. Rodewald
               Have you written your own real-time OS lately???

The best things in life aren't things.

-- 

To unsubscribe send "unsubscribe miami-talk-ml" to
"[EMAIL PROTECTED]". For help on list commands send "help" to
"[EMAIL PROTECTED]".


Reply via email to