Networking Forums

Networking Forums > Computer Networking > Windows Networking > Basic Firewall - ports that should be close are open...

Reply
Thread Tools Display Modes

Basic Firewall - ports that should be close are open...

 
 
Gabriele
Guest
Posts: n/a

 
      09-20-2005, 11:21 AM
I'm a newbie to basic firewall...
I have a win2003 server with IIS running some low traffic sites and
windows file sharing (port 139). I would like to use the server also as
vpn server (extremely low traffic) so i tried to configure RRAS and
Basic Firewall (i turned off windows firewall).
I configured NAT/Basic firewall to manage the public interface and I
checked the Basic Firewall radio button. I configured the exceptions on
the public interface via the Services and Ports tab in order to publish
ports 80, 139, 3389. For 80 and 3389 there was altready an entry, for
139 i added a new entry following other services pattern (the private
address is the same as the public address and incoming port is the same
as outcoming port).
Results:
The port 21 is open also if the service/port entry is not checked.
The port 139 is stealthed and there's no way to open it.
Ports 80 and 3389 are working correctly.

What about 21 (that should be closed) and 139 (that should be open)?

 
Reply With Quote
 
 
 
 
Dmitry Korolyov [MVP]
Guest
Posts: n/a

 
      09-20-2005, 04:50 PM
There is a basic and very simple rule for configuring firewalls:

1. Close all ports
2. Open only 1 port needed to access one of your services on the
firewall/internal network
3. Repeat step 3 for each service that needs to be accessible from outside.

--
Dmitry Korolyov [(E-Mail Removed)]
MVP: Windows Server - Directory Services


"Gabriele" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed) oups.com...
> I'm a newbie to basic firewall...
> I have a win2003 server with IIS running some low traffic sites and
> windows file sharing (port 139). I would like to use the server also as
> vpn server (extremely low traffic) so i tried to configure RRAS and
> Basic Firewall (i turned off windows firewall).
> I configured NAT/Basic firewall to manage the public interface and I
> checked the Basic Firewall radio button. I configured the exceptions on
> the public interface via the Services and Ports tab in order to publish
> ports 80, 139, 3389. For 80 and 3389 there was altready an entry, for
> 139 i added a new entry following other services pattern (the private
> address is the same as the public address and incoming port is the same
> as outcoming port).
> Results:
> The port 21 is open also if the service/port entry is not checked.
> The port 139 is stealthed and there's no way to open it.
> Ports 80 and 3389 are working correctly.
>
> What about 21 (that should be closed) and 139 (that should be open)?
>



 
Reply With Quote
 
Gabriele
Guest
Posts: n/a

 
      09-21-2005, 08:21 AM
That was the idea... The checking or unchecking FTP Service entry has
no effect on the firewall (port 21 always open); checking or unchecking
Netbios service has no effect (port 139 always closed).

Any other suggestion?

Thanks,
Gabriele

 
Reply With Quote
 
Dmitry Korolyov [MVP]
Guest
Posts: n/a

 
      09-21-2005, 04:53 PM
Well, I'm not quite sure about built-in firewall's features in details, but
they worked fine for me. How did you check the ports? nmap or something
alike?

--
Dmitry Korolyov [(E-Mail Removed)]
MVP: Windows Server - Directory Services


"Gabriele" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed) ups.com...
> That was the idea... The checking or unchecking FTP Service entry has
> no effect on the firewall (port 21 always open); checking or unchecking
> Netbios service has no effect (port 139 always closed).
>
> Any other suggestion?
>
> Thanks,
> Gabriele
>



 
Reply With Quote
 
Frankster
Guest
Posts: n/a

 
      09-21-2005, 05:29 PM
Go into "Scope" under the rule "Edit" function and you will probably see
that you are only affecting the scope you have defined by changing your
settings.

-Frank

"Gabriele" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed) oups.com...
> I'm a newbie to basic firewall...
> I have a win2003 server with IIS running some low traffic sites and
> windows file sharing (port 139). I would like to use the server also as
> vpn server (extremely low traffic) so i tried to configure RRAS and
> Basic Firewall (i turned off windows firewall).
> I configured NAT/Basic firewall to manage the public interface and I
> checked the Basic Firewall radio button. I configured the exceptions on
> the public interface via the Services and Ports tab in order to publish
> ports 80, 139, 3389. For 80 and 3389 there was altready an entry, for
> 139 i added a new entry following other services pattern (the private
> address is the same as the public address and incoming port is the same
> as outcoming port).
> Results:
> The port 21 is open also if the service/port entry is not checked.
> The port 139 is stealthed and there's no way to open it.
> Ports 80 and 3389 are working correctly.
>
> What about 21 (that should be closed) and 139 (that should be open)?
>



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
What ports must be open on firewall to allow RDS/TS CAL checkouts? MattMJF Windows Networking 2 02-25-2010 07:08 PM
Sending a "ping": Which (ICMP) ports must be open in firewall to receive answer ? Peter Waibel Linux Networking 2 03-29-2007 05:49 PM
Builtin Firewall Blocks Localhost Access (Even Open Ports) Michael Kennedy [UB] Windows Networking 1 06-30-2004 11:42 AM
port 139 open , how to close it ? E. Polinski Linux Networking 2 01-03-2004 05:51 PM
Newbie Q: How to open ipchains firewall to forward ports to XBox Live George Linux Networking 0 12-23-2003 06:49 PM



1 2 3 4 5 6 7 8 9 10 11