Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

hardware firewall and open ports...

Thread Tools
 
Search this Thread
 
Old Jan 2, 2003 | 03:23 PM
  #1  
Fosters's Avatar
Fosters
Thread Starter
Scooby Regular
 
Joined: Jul 2000
Posts: 2,145
Likes: 0
From: Islington
Post

A friend (who is the network admin today ) has gone to shields up section of www.grc.com and it told her that her http and smtp are vulnerable. I also port sniffed her machine and found that 4 other ports were open.

I don't know much about hardware firewalls, but shouldn't all that be closed off? is it just a case of setting the firewall up properly?

assistance appreciated here.

Mike
Reply
Old Jan 2, 2003 | 03:26 PM
  #2  
ChrisB's Avatar
ChrisB
Moderator
 
Joined: Dec 1998
Posts: 23,573
Likes: 0
From: Staffs
Post

Do you know what firewall it is?

Something like the SonicWall in an out of the box config has everything closed and then you open up the holes you want.
Reply
Old Jan 2, 2003 | 03:28 PM
  #3  
Fosters's Avatar
Fosters
Thread Starter
Scooby Regular
 
Joined: Jul 2000
Posts: 2,145
Likes: 0
From: Islington
Post

She says its Symantec and... drum roll... "yellow and hub looking"
Reply
Old Jan 2, 2003 | 03:40 PM
  #4  
ChrisB's Avatar
ChrisB
Moderator
 
Joined: Dec 1998
Posts: 23,573
Likes: 0
From: Staffs
Post



Sounds like a Symantec Firewall Appliance jobbie, similar to the SonicWall.

Not a clue about it though!

http://enterprisesecurity.symantec.c...uctID=63&EID=0
Reply
Old Jan 2, 2003 | 03:41 PM
  #5  
JackClark's Avatar
JackClark
Scooby Senior
25 Year Member
Liked
Loved
Community Favorite
 
Joined: Dec 2000
Posts: 20,896
Likes: 53
From: Overdosed on LCD
Post

One of these most likely
Reply
Old Jan 2, 2003 | 03:48 PM
  #6  
ChrisB's Avatar
ChrisB
Moderator
 
Joined: Dec 1998
Posts: 23,573
Likes: 0
From: Staffs
Post

Thinking about it...

Having SMTP open makes sense - I would guess they run a mail server which the outside world needs to talk to. You'll find SMTP open on our firewall.

HTTP is less clear cut. Do they host their own web site? Or maybe HTTP is open for remote webmail?

What are the other port numbers?
Reply
Old Jan 2, 2003 | 03:53 PM
  #7  
Fosters's Avatar
Fosters
Thread Starter
Scooby Regular
 
Joined: Jul 2000
Posts: 2,145
Likes: 0
From: Islington
Post

it's a Symantec Firewall/VPN Appliance 100

and the ports I found are: 389, 1002, 1002 and 1720 although I didn't sniff past port 2000
Reply
Old Jan 2, 2003 | 04:10 PM
  #8  
Jeff Wiltshire's Avatar
Jeff Wiltshire
Scooby Regular
 
Joined: Nov 2000
Posts: 2,021
Likes: 1
From: 412 Wheel HP Audi RS4
Post

The Symantec box is based on Raptor which does an odd combination of Port Filtering, Stateful Inspection & Proxy....

389 & 1002 are LDAP ports and 1720 is H323 .... I would guess that these are configured in the Proxy side of the box. The symantec product really does need to be set-up properly.

I would also not really on the Gibson Research web page.....!


Jeff
Reply
Old Feb 1, 2003 | 04:09 PM
  #9  
ChrisB's Avatar
ChrisB
Moderator
 
Joined: Dec 1998
Posts: 23,573
Likes: 0
From: Staffs
Post

389 is LDAP, 1002 no idea, 1720 is H323.

389 and 1720 make me think of something like NetMeeting or something for conferencing?

{Edit 'cos I can't read }

[Edited by ChrisB - 1/2/2003 4:12:20 PM]
Reply
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
gazzawrx
Non Car Related Items For sale
13
Oct 17, 2015 06:51 PM
Matt_182
General Technical
0
Sep 30, 2015 03:20 PM
dantiel
General Technical
8
Sep 29, 2015 11:33 PM
alcazar
Computer & Technology Related
2
Sep 29, 2015 07:18 PM




All times are GMT +1. The time now is 06:08 PM.