I want to tighten up our office ADSL router's rules on outgoing traffic
to reduce the risk from malware. The question is, what ports are
essential for a basic office LAN web/email setup?
These are the outgoing ports it looks like I need:
smtp 25 tcp
pop3 110 tcp
ftp 20-21 tcp (for downloading only, not serving)
dns 53 tcp+udp
http 80 tcp
https 443 tcp
timeserver 123 udp
Have I missed anything? and are those ports correct? With ftp I wasn't
sure if I need 20 & 21 or just 21. We also have Windows Update and
Norton AV running, do these use port 80 for getting stuff or do they
have dedicated ports?
We have all incoming ports blocked at present, though I notice that my
personal firewall rules at home have the timeserver and ftp ports open
both in and out, I'm not sure if that's right or not - I seem to recall
that ftp uses 21 out and 20 in.
--
__________________________________________________ ____
If only one could get that wonderful feeling of
accomplishment without having to accomplish anything.
__________________________________________________ ____
Take a break at the Last Stop Cafe:
http://www.xerez.demon.co.uk/
Reply-to address for email: mailreply AT xerez.demon.co.uk