Firewall Wizards mailing list archives
Re: Ports 256,257,258 open on FW-1
From: Chris Brenton <cbrenton () sover net>
Date: Mon, 14 Dec 1998 16:37:07 -0500
Dave Whitlow wrote:
And whilst you're doing this I suggest you check out the other bad defaults in policy/properties. Chances are you're allowing icmp, dns (udp & zone), rip and other things through. You may even be offering your snmp info (either NT or FW-1 mib). As someone else noted, about 9/10 FW-1 installations look like this. I always advise you switch off all these defaults and then add rules to allow the things you *really* need.
I agree completely. In fact, I posted a write up about this to the FW-1 mailing list a few months ago that outlines the problem including screen captures and log file entries. I also describe exactly what you need to change in order to lock down the policy rules. If anyone is interested in this write up, please drop me mail. I would post it to the list but it includes about 40K worth of graphic screen captures. Cheers, Chris -- ************************************** cbrenton () sover net * Multiprotocol Network Design & Troubleshooting http://www.amazon.com/exec/obidos/ISBN=0782120822/0740-8883012-887529 * Mastering Network Security http://www.amazon.com/exec/obidos/ISBN%3D0782123430/002-0346046-8151850
Current thread:
- Ports 256,257,258 open on FW-1 John Lauderdale (Dec 11)
- Re: Ports 256,257,258 open on FW-1 Chris Brenton (Dec 14)
- Re: Ports 256,257,258 open on FW-1 Dave Whitlow (Dec 15)
- Re: Ports 256,257,258 open on FW-1 Chris Brenton (Dec 15)
- Re: Ports 256,257,258 open on FW-1 Randolf-Heiko Skerka (Dec 15)
- Re: Ports 256,257,258 open on FW-1 Dave Whitlow (Dec 15)
- Re: Ports 256,257,258 open on FW-1 Darren Reed (Dec 14)
- Re: Ports 256,257,258 open on FW-1 Peter J. Cherny (Dec 15)
- Re: Ports 256,257,258 open on FW-1 Lart (Dec 15)
- RE: Ports 256,257,258 open on FW-1 Joe Ippolito (Dec 18)
- <Possible follow-ups>
- Re: Ports 256,257,258 open on FW-1 mark s. kassem (Dec 12)
- RE: Ports 256,257,258 open on FW-1 Houser David DW (Dec 14)
- Re: Ports 256,257,258 open on FW-1 Ryan Russell (Dec 14)
- Re: Ports 256,257,258 open on FW-1 Bruce B. Platt (Dec 18)
- Re: Ports 256,257,258 open on FW-1 jgalvin (Dec 22)
(Thread continues...)
- Re: Ports 256,257,258 open on FW-1 Chris Brenton (Dec 14)
