Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie

What SERVICES TO BLOCK ON A FIREWALL

Options
  • 05-09-2005 9:24pm
    #1
    Registered Users Posts: 2,839 ✭✭✭


    Ok

    Id like to know what are the common ports ye Network Admins block by default


    Limewire TCP 6346
    E-Donkey TCP 4662
    E- Donkey UDP 9367
    Real Audio TCP 7070
    QuickTime ICMP 554
    WINMX TCP 6699 & 6257

    id like to see yer lists of services to block to stop users abusuing the connection to the net

    Thanks Guys


Comments

  • Closed Accounts Posts: 6,601 ✭✭✭Kali


    Denying specific ports is bad. Deny all then permit specified ports.

    In here everything is denied bar:
    80 (with specific rules blocking httptunnel IPs), 25 (to specific MTAs only), 110 (again to specific servers), 22 (ssh), 123 (ntp), 53 (dns) and outbound icmp traffic.


  • Registered Users Posts: 2,518 ✭✭✭Hecate


    Usually you have a default drop rule at the beginning or end of your ruleset, where you put it depends on how the firewall in question evaluates its rules of course. Out of the box, a lot of popular firewalls are configured to drop all traffic anyway.

    You then start allowing what you want, and only what you want, in and out.


  • Registered Users Posts: 14,990 ✭✭✭✭loyatemu


    Kali wrote:
    Denying specific ports is bad. Deny all then permit specified ports.

    In here everything is denied bar:
    80 (with specific rules blocking httptunnel IPs), 25 (to specific MTAs only), 110 (again to specific servers), 22 (ssh), 123 (ntp), 53 (dns) and outbound icmp traffic.

    might want to allow 443 for https as well.


Advertisement