[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[no subject]
- <!--x-content-type: text/plain -->
- <!--x-date: Tue Jun 8 12:54:46 2004 -->
- <!--x-from-r13: wbanguna.tynff ng voo.tngrpu.rqh (Xbanguna Uynff) -->
- <!--x-message-id: 1086713613.14804.58.camel@ibb-250 -->
- <!--x-reference: 04Jun3.122004-0400_edt.360380-[email protected] -->
- <!--x-reference: 1086281507.13042.34.camel@ibb-250 -->
- <!--x-reference: [email protected] -->
- <!--x-reference: [email protected] -->
- <!--x-reference: 1086700443.14804.11.camel@ibb-250 -->
- <!--x-reference: [email protected] -->
- <!--x-reference: 1086701227.14805.13.camel@ibb-250 -->
- <!--x-reference: 1086701435.14796.17.camel@ibb-250 -->
- <!--x-reference: [email protected] --> "http://www.w3.org/TR/html4/loose.dtd">
- <!--x-subject: [ale] Open Source Firewall for Windows 2000/XP? -->
- <li><em>date</em>: Tue Jun 8 12:54:46 2004</li>
- <li><em>from</em>: jonathan.glass at ibb.gatech.edu (Jonathan Glass)</li>
- <li><em>in-reply-to</em>: <<a href="msg00187.html">[email protected]</a>></li>
- <li><em>references</em>: <<a href="msg00049.html">[email protected]</a>> <1086281507.13042.34.camel@ibb-250> <<a href="msg00178.html">[email protected]</a>> <<a href="msg00181.html">[email protected]</a>> <1086700443.14804.11.camel@ibb-250> <<a href="msg00184.html">[email protected]</a>> <1086701227.14805.13.camel@ibb-250> <1086701435.14796.17.camel@ibb-250> <<a href="msg00187.html">[email protected]</a>></li>
- <li><em>subject</em>: [ale] Open Source Firewall for Windows 2000/XP?</li>
Should be minimal, since you're only restricting incoming
communication. That being said, test and let me know!
> 2) Where can the cool script that you generated be put so that protection is
> automagically invoked when the machine is booted?
IIRC, this script is making changes to the registry, so you run it once,
and it stays set.
> 3) It seems that the scripts only block certain ports. Is it possible to
> specify blackage of all incoming ports (i.e. [*=0:*,TCP]?) Never mind I found
> it here:
Thanks for the info.
> ---------------------------------------------
> <a rel="nofollow" href="http://win2k.uwaterloo.ca/IP_Security/Servers_IPSEC.htm">http://win2k.uwaterloo.ca/IP_Security/Servers_IPSEC.htm</a>
>
> example:
> ipsecpol -x -w reg -p "UW DC Policy" -r "TCP Blocked" -n BLOCK -f *+0::TCP
> #The first blocks all TCP traffic to and from anywhere to the server where
> #this is run.
>
> A followup explanation of the filter specification:
>
> Our Filter Explained:
>
> '-f 129.97.*.*+0::TCP' defines a source mask of 129.97.*.* meaning from
> anywhere on campus.
>
> The '+' mirrors the filter meaning source to destination and destination to
> source, [BAJ Note: use an '=' for a filter in a single direction]
>
> The '0' defines our destination as the IP address of the workstation it's
> defined on,
>
> and the port controlled is all TCP since there is no number between the two
> colons.
> ---------------------------------------------
>
>
> A bit overreaching, but gives enough information in order to tailor the
> policy.
>
> I see two possible configs:
>
> 1) Machine on unprotected network. All incoming ports (including port 500)
> closed. Would the machine function in this configuration?
Yes, with a possible problem in a domain configuration. We had some
strange behavior when we blocked all incoming ports. That's why there
is a hole for the local subnet for file and print sharing and RPC
traffic to the PDC & File servers. I didn't have a great deal of time
to work with it, so I left it as you see it.
> 2) Machine on firewall protected network. Wat ports would need to be open
> in order to get ordinary windows authentication and sharing services?
Should be port 135 for the RPC stuff, then 445 (2000/XP only network),
or 139 for a WinNT/9x network.
> Thanks for all the help Jonathan. Oh BTW the last name is Jeff, not Jeffy as
> you have in your acknowlgement on your web page.
Oops! Typo corrected.
>
> BAJ
> _______________________________________________
> Ale mailing list
> Ale at ale.org
> <a rel="nofollow" href="http://www.ale.org/mailman/listinfo/ale">http://www.ale.org/mailman/listinfo/ale</a>
--
Jonathan Glass
Systems Support Specialist II
Institute for Bioengineering & Bioscience
Georgia Institute of Technology
Email: jonathan.glass at ibb.gatech.edu
Office: 404-385-0127
Fax: 404-894-2291
</pre>
<!--X-Body-of-Message-End-->
<!--X-MsgBody-End-->
<!--X-Follow-Ups-->
<hr>
<!--X-Follow-Ups-End-->
<!--X-References-->
<ul><li><strong>References</strong>:
<ul>
<li><strong><a name="00049" href="msg00049.html">[ale] Open Source Firewall for Windows 2000/XP?</a></strong>
<ul><li><em>From:</em> jonathan at xcorps.net (Jonathan Rickman)</li></ul></li>
<li><strong><a name="00050" href="msg00050.html">[ale] Open Source Firewall for Windows 2000/XP?</a></strong>
<ul><li><em>From:</em> jonathan.glass at ibb.gatech.edu (Jonathan Glass)</li></ul></li>
<li><strong><a name="00178" href="msg00178.html">[ale] Open Source Firewall for Windows 2000/XP?</a></strong>
<ul><li><em>From:</em> jonathan.glass at ibb.gatech.edu (Jonathan Glass)</li></ul></li>
<li><strong><a name="00181" href="msg00181.html">[ale] Open Source Firewall for Windows 2000/XP?</a></strong>
<ul><li><em>From:</em> esoteric at 3times25.net (Geoffrey)</li></ul></li>
<li><strong><a name="00183" href="msg00183.html">[ale] Open Source Firewall for Windows 2000/XP?</a></strong>
<ul><li><em>From:</em> jonathan.glass at ibb.gatech.edu (Jonathan Glass)</li></ul></li>
<li><strong><a name="00184" href="msg00184.html">[ale] Open Source Firewall for Windows 2000/XP?</a></strong>
<ul><li><em>From:</em> esoteric at 3times25.net (Geoffrey)</li></ul></li>
<li><strong><a name="00185" href="msg00185.html">[ale] Open Source Firewall for Windows 2000/XP?</a></strong>
<ul><li><em>From:</em> jonathan.glass at ibb.gatech.edu (Jonathan Glass)</li></ul></li>
<li><strong><a name="00186" href="msg00186.html">[ale] Open Source Firewall for Windows 2000/XP?</a></strong>
<ul><li><em>From:</em> jonathan.glass at ibb.gatech.edu (Jonathan Glass)</li></ul></li>
<li><strong><a name="00187" href="msg00187.html">[ale] Open Source Firewall for Windows 2000/XP?</a></strong>
<ul><li><em>From:</em> byron at cc.gatech.edu (Byron A Jeff)</li></ul></li>
</ul></li></ul>
<!--X-References-End-->
<!--X-BotPNI-->
<ul>
<li>Prev by Date:
<strong><a href="msg00187.html">[ale] Open Source Firewall for Windows 2000/XP?</a></strong>
</li>
<li>Next by Date:
<strong><a href="msg00189.html">[ale] iTunes Server under Linux</a></strong>
</li>
<li>Previous by thread:
<strong><a href="msg00187.html">[ale] Open Source Firewall for Windows 2000/XP?</a></strong>
</li>
<li>Next by thread:
<strong><a href="msg00051.html">[ale] Open Source Firewall for Windows 2000/XP?</a></strong>
</li>
<li>Index(es):
<ul>
<li><a href="maillist.html#00188"><strong>Date</strong></a></li>
<li><a href="threads.html#00188"><strong>Thread</strong></a></li>
</ul>
</li>
</ul>
<!--X-BotPNI-End-->
<!--X-User-Footer-->
<!--X-User-Footer-End-->
</body>
</html>