Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

little help - ports to let through LAN firewall?

Thread Tools
 
Search this Thread
 
Old 24 October 2007, 02:57 PM
  #1  
spectrum48k
Scooby Regular
Thread Starter
 
spectrum48k's Avatar
 
Join Date: Feb 2006
Posts: 2,519
Likes: 0
Received 0 Likes on 0 Posts
Default little help - ports to let through LAN firewall?

I'm setting up a new firewall appliance this weekend and am just making a note of the typical ports i'll need to open up for the network:

HTTP, 80
RDP, 3389
POP3, 110
SMTP, 25
VNC
PING
FTP, 21
DNS, 53, UDP
HTTPS, 443

anything else ?

Last edited by spectrum48k; 24 October 2007 at 03:28 PM.
Old 24 October 2007, 02:59 PM
  #2  
bgood
Scooby Regular
iTrader: (2)
 
bgood's Avatar
 
Join Date: Sep 2004
Location: If you rev it, they will come!
Posts: 2,025
Likes: 0
Received 0 Likes on 0 Posts
Default

443 HTTPS
Old 24 October 2007, 03:00 PM
  #3  
mike1210
Scooby Regular
 
mike1210's Avatar
 
Join Date: Apr 2004
Location: Cardiff
Posts: 1,928
Likes: 0
Received 0 Likes on 0 Posts
Default

I assume you mean going outwards

HTTPS i'd add

booooger beaten to it
Old 24 October 2007, 03:02 PM
  #4  
mike1210
Scooby Regular
 
mike1210's Avatar
 
Join Date: Apr 2004
Location: Cardiff
Posts: 1,928
Likes: 0
Received 0 Likes on 0 Posts
Default

FTP may be an **** unless the firewall can inspect that protocol,

Out of interest what firewall is it?
Old 24 October 2007, 03:07 PM
  #5  
mike1210
Scooby Regular
 
mike1210's Avatar
 
Join Date: Apr 2004
Location: Cardiff
Posts: 1,928
Likes: 0
Received 0 Likes on 0 Posts
Default

DNS Lookups also if for going out, UDP port 53
Old 24 October 2007, 03:27 PM
  #6  
spectrum48k
Scooby Regular
Thread Starter
 
spectrum48k's Avatar
 
Join Date: Feb 2006
Posts: 2,519
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by mike1210
FTP may be an **** unless the firewall can inspect that protocol,

Out of interest what firewall is it?
draytek vigor 2930 firewall appliance
supports Stateful packet inspection, etc...

why would FTP be an "****" ? Can you enlighten me, as I'm a newbie with this stuff - do you mean from a port forwarding point of view over NAT ?

Last edited by spectrum48k; 24 October 2007 at 03:30 PM.
Old 24 October 2007, 03:31 PM
  #7  
unfeasablylargegonads
Scooby Regular
iTrader: (3)
 
unfeasablylargegonads's Avatar
 
Join Date: Aug 2004
Location: Cambs
Posts: 701
Likes: 0
Received 0 Likes on 0 Posts
Default

FTP & NAT:

The File Transfer Protocol (FTP) and Your Firewall / Network Address Translation (NAT) Router / Load Balancing Router
Old 24 October 2007, 03:36 PM
  #8  
mike1210
Scooby Regular
 
mike1210's Avatar
 
Join Date: Apr 2004
Location: Cardiff
Posts: 1,928
Likes: 0
Received 0 Likes on 0 Posts
Default

Yes what big ***** said

My Cisco 877W copes with it fine but my old Draytek 2600 wouldn't, limiting outgoing ports. With no outgoing ports limited it will be fine.

as an example nero website, download via FTP it makes a port 21 connection and a random port above 1024, with block except certain ports this causes problems

IIRC the 3300 has an FTP inspect feature but I didn't see that on the 2930

Id also be wary of allowing VNC out as well, especially if it's unencypted (as VNC can be). RDP is encrypted but users can share there drives, this could introduce a virus onto the network. From a security dudes point of view
Old 24 October 2007, 04:53 PM
  #9  
spectrum48k
Scooby Regular
Thread Starter
 
spectrum48k's Avatar
 
Join Date: Feb 2006
Posts: 2,519
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by mike1210
Yes what big ***** said

My Cisco 877W copes with it fine but my old Draytek 2600 wouldn't, limiting outgoing ports. With no outgoing ports limited it will be fine.

as an example nero website, download via FTP it makes a port 21 connection and a random port above 1024, with block except certain ports this causes problems

IIRC the 3300 has an FTP inspect feature but I didn't see that on the 2930

Id also be wary of allowing VNC out as well, especially if it's unencypted (as VNC can be). RDP is encrypted but users can share there drives, this could introduce a virus onto the network. From a security dudes point of view
good info, thanks for the link big bollocks

there's only 1 VNC connection, where a trusted remote client will be using it to remotely VPN into a workstation.

As for RDP, there's only me who'll use it to administer the workstations behind the firewall and I trust my Kaspersky to keep me clear of viri !

I'll check out the FTP issue

Last edited by spectrum48k; 24 October 2007 at 05:31 PM.
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
JimBowen
ICE
5
02 July 2023 01:54 PM
KAS35RSTI
Subaru
27
04 November 2021 07:12 PM
Mattybr5@MB Developments
Full Cars Breaking For Spares
28
28 December 2015 11:07 PM
Ganz1983
Subaru
5
02 October 2015 09:22 AM
dantiel
General Technical
8
29 September 2015 11:33 PM



Quick Reply: little help - ports to let through LAN firewall?



All times are GMT +1. The time now is 10:39 AM.