Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

little help - ports to let through LAN firewall?

Thread Tools
 
Search this Thread
 
Old Oct 24, 2007 | 02:57 PM
  #1  
spectrum48k's Avatar
spectrum48k
Thread Starter
Scooby Regular
 
Joined: Feb 2006
Posts: 2,519
Likes: 0
Default little help - ports to let through LAN firewall?

I'm setting up a new firewall appliance this weekend and am just making a note of the typical ports i'll need to open up for the network:

HTTP, 80
RDP, 3389
POP3, 110
SMTP, 25
VNC
PING
FTP, 21
DNS, 53, UDP
HTTPS, 443

anything else ?

Last edited by spectrum48k; Oct 24, 2007 at 03:28 PM.
Reply
Old Oct 24, 2007 | 02:59 PM
  #2  
bgood's Avatar
bgood
Scooby Regular
iTrader: (2)
 
Joined: Sep 2004
Posts: 2,025
Likes: 0
From: If you rev it, they will come!
Default

443 HTTPS
Reply
Old Oct 24, 2007 | 03:00 PM
  #3  
mike1210's Avatar
mike1210
Scooby Regular
 
Joined: Apr 2004
Posts: 1,928
Likes: 0
From: Cardiff
Default

I assume you mean going outwards

HTTPS i'd add

booooger beaten to it
Reply
Old Oct 24, 2007 | 03:02 PM
  #4  
mike1210's Avatar
mike1210
Scooby Regular
 
Joined: Apr 2004
Posts: 1,928
Likes: 0
From: Cardiff
Default

FTP may be an **** unless the firewall can inspect that protocol,

Out of interest what firewall is it?
Reply
Old Oct 24, 2007 | 03:07 PM
  #5  
mike1210's Avatar
mike1210
Scooby Regular
 
Joined: Apr 2004
Posts: 1,928
Likes: 0
From: Cardiff
Default

DNS Lookups also if for going out, UDP port 53
Reply
Old Oct 24, 2007 | 03:27 PM
  #6  
spectrum48k's Avatar
spectrum48k
Thread Starter
Scooby Regular
 
Joined: Feb 2006
Posts: 2,519
Likes: 0
Default

Originally Posted by mike1210
FTP may be an **** unless the firewall can inspect that protocol,

Out of interest what firewall is it?
draytek vigor 2930 firewall appliance
supports Stateful packet inspection, etc...

why would FTP be an "****" ? Can you enlighten me, as I'm a newbie with this stuff - do you mean from a port forwarding point of view over NAT ?

Last edited by spectrum48k; Oct 24, 2007 at 03:30 PM.
Reply
Old Oct 24, 2007 | 03:31 PM
  #7  
unfeasablylargegonads's Avatar
unfeasablylargegonads
Scooby Regular
iTrader: (3)
 
Joined: Aug 2004
Posts: 701
Likes: 0
From: Cambs
Default

FTP & NAT:

The File Transfer Protocol (FTP) and Your Firewall / Network Address Translation (NAT) Router / Load Balancing Router
Reply
Old Oct 24, 2007 | 03:36 PM
  #8  
mike1210's Avatar
mike1210
Scooby Regular
 
Joined: Apr 2004
Posts: 1,928
Likes: 0
From: Cardiff
Default

Yes what big ***** said

My Cisco 877W copes with it fine but my old Draytek 2600 wouldn't, limiting outgoing ports. With no outgoing ports limited it will be fine.

as an example nero website, download via FTP it makes a port 21 connection and a random port above 1024, with block except certain ports this causes problems

IIRC the 3300 has an FTP inspect feature but I didn't see that on the 2930

Id also be wary of allowing VNC out as well, especially if it's unencypted (as VNC can be). RDP is encrypted but users can share there drives, this could introduce a virus onto the network. From a security dudes point of view
Reply
Old Oct 24, 2007 | 04:53 PM
  #9  
spectrum48k's Avatar
spectrum48k
Thread Starter
Scooby Regular
 
Joined: Feb 2006
Posts: 2,519
Likes: 0
Default

Originally Posted by mike1210
Yes what big ***** said

My Cisco 877W copes with it fine but my old Draytek 2600 wouldn't, limiting outgoing ports. With no outgoing ports limited it will be fine.

as an example nero website, download via FTP it makes a port 21 connection and a random port above 1024, with block except certain ports this causes problems

IIRC the 3300 has an FTP inspect feature but I didn't see that on the 2930

Id also be wary of allowing VNC out as well, especially if it's unencypted (as VNC can be). RDP is encrypted but users can share there drives, this could introduce a virus onto the network. From a security dudes point of view
good info, thanks for the link big bollocks

there's only 1 VNC connection, where a trusted remote client will be using it to remotely VPN into a workstation.

As for RDP, there's only me who'll use it to administer the workstations behind the firewall and I trust my Kaspersky to keep me clear of viri !

I'll check out the FTP issue

Last edited by spectrum48k; Oct 24, 2007 at 05:31 PM.
Reply
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
JimBowen
ICE
5
Jul 2, 2023 01:54 PM
KAS35RSTI
Subaru
27
Nov 4, 2021 07:12 PM
Mattybr5@MB Developments
Full Cars Breaking For Spares
28
Dec 28, 2015 11:07 PM
Ganz1983
Subaru
5
Oct 2, 2015 09:22 AM
dantiel
General Technical
8
Sep 29, 2015 11:33 PM




All times are GMT +1. The time now is 06:57 PM.