On 6 Apr 2000, Rhett R. Rodewald wrote:
> >> Anyway, is there a way to make this work without opening up _all_ the ports
> >> from 5000 to 65555???
>
> >If the other system may use any port from 5000-65535, then no, but:
> >1) If no systems on your LAN have services on ports in that range, it
> >doesn't matter.
>
> OK, I know this is a wide open, leading question, but to the best of anyone's
> knowledge, do any (important) services use ports above 5000? Is Windows (or
> any other OS) known to be vulnerable to probing in this range?
*You* have to install the services for it to matter. :-)
There are some things like multiplayer games that use specific port
numbers in that range, and there are things where the port is
configurable.
What really wreaks havoc with firewalls is the Unix RPC stuff, where
services get assigned ports dynamically, and the client contacts the
portmapper to determine the current assignment for a given service. The
poor firewall doesn't easily have a clue what's going on.
> >2) You can set up the firewall entries to allow the unrestricted access
> >only for the DNS servers' IP addresses. This isn't bulletproof, but it at
> >least makes it more difficult for an attacker. Of course there's no way
> >to do this with dynamic DNS IPs.
>
> I assume this requires a seperate entry for each DNS server? Obviously, I
> don't want to open up too wide of a range of addresses, or I wouldn't bother
> in the first place.
Yes. If you have multiple ISPs, you might just enter all the servers
without worrying about whether you're including some currently "inactive"
ones. But if DNS IPs get changed, you need to update the firewall
settings.
Fred Wright
--
To unsubscribe send "unsubscribe miami-talk-ml" to
"[EMAIL PROTECTED]". For help on list commands send "help" to
"[EMAIL PROTECTED]".