Networking Forums

Networking Forums > Wireless Networking > Wireless Internet > Filter Ident port 113

Reply
Thread Tools Display Modes

Filter Ident port 113

 
 
Jefferis NoSpamme
Guest
Posts: n/a

 
      01-02-2005, 07:31 PM
I am finding that my wireless connection to my linksys router will not work
if I have this option on:

Filter IDENT (Port 113)

> Prevents outside intruders from attacking the router through the internet
> using service port 113.* Select Enable to prevent attack through this service
> port.* However, some applications may require this service port to be
> available. If needed, uncheck to allow those applications to work



What am I risking by trying that off?
Thanks

~~~~~~~~~~~~
Jefferis Peterson, Pres.
Web Design and Marketing
http://www.PetersonSales.com


 
Reply With Quote
 
 
 
 
Jeff Liebermann
Guest
Posts: n/a

 
      01-02-2005, 07:59 PM
On Sun, 02 Jan 2005 15:31:25 -0500, Jefferis NoSpamme
<(E-Mail Removed)> wrote:

>I am finding that my wireless connection to my linksys router will not work
>if I have this option on:
>
>Filter IDENT (Port 113)
>
>> Prevents outside intruders from attacking the router through the internet
>> using service port 113.* Select Enable to prevent attack through this service
>> port.* However, some applications may require this service port to be
>> available. If needed, uncheck to allow those applications to work

>
>What am I risking by trying that off?


Some mail servers use IDENT to authenticate the sending machine. My
ancient UUCP over TCP system does that and will not work with IDENT
turned off. If your email stops working, IDENT may be the problem.
Systems using a Squid cache also tend to use IDENT as it's on by
default.

Some reading:
http://kline.dal.net/exploits/ident.htm

--
Jeff Liebermann (E-Mail Removed)
150 Felker St #D http://www.LearnByDestroying.com
Santa Cruz CA 95060 AE6KS 831-336-2558
 
Reply With Quote
 
Airhead
Guest
Posts: n/a

 
      01-02-2005, 09:07 PM

"> >I am finding that my wireless connection to my linksys router will
not work
> >if I have this option on:
> >
> >Filter IDENT (Port 113)
> >
> >> Prevents outside intruders from attacking the router through the

internet
> >> using service port 113. Select Enable to prevent attack through

this service
> >> port. However, some applications may require this service port to

be
> >> available. If needed, uncheck to allow those applications to work

> >
> >What am I risking by trying that off?


The way I steath my 113 is to assign it as a distributed server with
an unused IP in my subnet.
Everything works and Shields up show it as stealth.
http:\\www.grc.com. Granted it works on
my asante router but no guarantee on yours.



>
> Some mail servers use IDENT to authenticate the sending machine. My
> ancient UUCP over TCP system does that and will not work with IDENT
> turned off. If your email stops working, IDENT may be the problem.
> Systems using a Squid cache also tend to use IDENT as it's on by
> default.
>
> Some reading:
> http://kline.dal.net/exploits/ident.htm
>
> --
> Jeff Liebermann (E-Mail Removed)
> 150 Felker St #D http://www.LearnByDestroying.com
> Santa Cruz CA 95060 AE6KS 831-336-2558


 
Reply With Quote
 
Neill Massello
Guest
Posts: n/a

 
      01-03-2005, 06:50 PM
Jeff Liebermann <(E-Mail Removed)> wrote:

> Some mail servers use IDENT to authenticate the sending machine. My
> ancient UUCP over TCP system does that and will not work with IDENT
> turned off. If your email stops working, IDENT may be the problem.
> Systems using a Squid cache also tend to use IDENT as it's on by
> default.
>
> Some reading:
> http://kline.dal.net/exploits/ident.htm


FWIW, two more links about ident that I scoured from a thread on identd
in comp.protocols.tcp-ip:

<http://jis.mit.edu./pipermail/saag/2002q1/000589.html>
<http://www.clock.org/~fair/opinion/identd.html>

My router has a setting to reject IDENT requests if no DMZ or packet
filter for port 113 has been established. It's better to provide a
formal rejection to an IDENT request rather than just ignoring it.

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Tc Filter - Port Ranges Calculate Mask Value anshul makkar Linux Networking 4 10-23-2007 08:17 PM
Sky ( via Easynet LLU ) port filter query ToxOgrady Broadband 29 01-09-2007 09:01 PM
Isn't a NAT router supposed to filter out port scans? Martin Underwood Home Networking 5 10-16-2005 11:57 AM
squidGuard with ident Mark Atherton Linux Networking 0 03-06-2005 08:28 PM
ident Anders Linux Networking 1 10-02-2003 04:58 PM



1 2 3 4 5 6 7 8 9 10 11