Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

hardware firewall and open ports...

Thread Tools
 
Search this Thread
 
Old 02 January 2003, 03:23 PM
  #1  
Fosters
Scooby Regular
Thread Starter
 
Fosters's Avatar
 
Join Date: Jul 2000
Location: Islington
Posts: 2,145
Likes: 0
Received 0 Likes on 0 Posts
Post

A friend (who is the network admin today ) has gone to shields up section of www.grc.com and it told her that her http and smtp are vulnerable. I also port sniffed her machine and found that 4 other ports were open.

I don't know much about hardware firewalls, but shouldn't all that be closed off? is it just a case of setting the firewall up properly?

assistance appreciated here.

Mike
Old 02 January 2003, 03:26 PM
  #2  
ChrisB
Moderator
 
ChrisB's Avatar
 
Join Date: Dec 1998
Location: Staffs
Posts: 23,573
Likes: 0
Received 0 Likes on 0 Posts
Post

Do you know what firewall it is?

Something like the SonicWall in an out of the box config has everything closed and then you open up the holes you want.
Old 02 January 2003, 03:28 PM
  #3  
Fosters
Scooby Regular
Thread Starter
 
Fosters's Avatar
 
Join Date: Jul 2000
Location: Islington
Posts: 2,145
Likes: 0
Received 0 Likes on 0 Posts
Post

She says its Symantec and... drum roll... "yellow and hub looking"
Old 02 January 2003, 03:40 PM
  #4  
ChrisB
Moderator
 
ChrisB's Avatar
 
Join Date: Dec 1998
Location: Staffs
Posts: 23,573
Likes: 0
Received 0 Likes on 0 Posts
Post



Sounds like a Symantec Firewall Appliance jobbie, similar to the SonicWall.

Not a clue about it though!

http://enterprisesecurity.symantec.c...uctID=63&EID=0
Old 02 January 2003, 03:41 PM
  #5  
JackClark
Scooby Senior
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Post

One of these most likely
Old 02 January 2003, 03:48 PM
  #6  
ChrisB
Moderator
 
ChrisB's Avatar
 
Join Date: Dec 1998
Location: Staffs
Posts: 23,573
Likes: 0
Received 0 Likes on 0 Posts
Post

Thinking about it...

Having SMTP open makes sense - I would guess they run a mail server which the outside world needs to talk to. You'll find SMTP open on our firewall.

HTTP is less clear cut. Do they host their own web site? Or maybe HTTP is open for remote webmail?

What are the other port numbers?
Old 02 January 2003, 03:53 PM
  #7  
Fosters
Scooby Regular
Thread Starter
 
Fosters's Avatar
 
Join Date: Jul 2000
Location: Islington
Posts: 2,145
Likes: 0
Received 0 Likes on 0 Posts
Post

it's a Symantec Firewall/VPN Appliance 100

and the ports I found are: 389, 1002, 1002 and 1720 although I didn't sniff past port 2000
Old 02 January 2003, 04:10 PM
  #8  
Jeff Wiltshire
Scooby Regular
 
Jeff Wiltshire's Avatar
 
Join Date: Nov 2000
Location: 412 Wheel HP Audi RS4
Posts: 2,021
Likes: 0
Received 1 Like on 1 Post
Post

The Symantec box is based on Raptor which does an odd combination of Port Filtering, Stateful Inspection & Proxy....

389 & 1002 are LDAP ports and 1720 is H323 .... I would guess that these are configured in the Proxy side of the box. The symantec product really does need to be set-up properly.

I would also not really on the Gibson Research web page.....!


Jeff
Old 01 February 2003, 04:09 PM
  #9  
ChrisB
Moderator
 
ChrisB's Avatar
 
Join Date: Dec 1998
Location: Staffs
Posts: 23,573
Likes: 0
Received 0 Likes on 0 Posts
Post

389 is LDAP, 1002 no idea, 1720 is H323.

389 and 1720 make me think of something like NetMeeting or something for conferencing?

{Edit 'cos I can't read }

[Edited by ChrisB - 1/2/2003 4:12:20 PM]
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
gazzawrx
Non Car Related Items For sale
13
17 October 2015 06:51 PM
Matt_182
General Technical
0
30 September 2015 03:20 PM
dantiel
General Technical
8
29 September 2015 11:33 PM
alcazar
Computer & Technology Related
2
29 September 2015 07:18 PM



Quick Reply: hardware firewall and open ports...



All times are GMT +1. The time now is 03:44 PM.