Networking Forums

Networking Forums > Computer Networking > Windows Networking > Port reporter and firewall question

Reply
Thread Tools Display Modes

Port reporter and firewall question

 
 
BG
Guest
Posts: n/a

 
      06-30-2005, 03:35 PM
I have the Firewall setup to block traffic on port 445, except for a custom
selection of addresses and I still see connections on local port 445 from IP
addresses outside the range. Does anyone have any experience on comparing
how port reporter shows connections and the settings in the firewall?

For example, say I have a network of computers with IP addresses of
131.180.240..xx and a subnet mask of 255.255.254.0. I only want traffic to
come from that network. I set the custom exception to
131.180.240.0/255.255.254.0. Is my custom exception list correct? Port
reporter is showing connections to port 445 from an address like
131.180.200.20.

 
Reply With Quote
 
 
 
 
Phillip Windell
Guest
Posts: n/a

 
      06-30-2005, 04:24 PM
"BG" <(E-Mail Removed)> wrote in message
news:9D233D00-6177-4001-A872-(E-Mail Removed)...
> I have the Firewall setup to block traffic on port 445, except for a

custom
> selection of addresses and I still see connections on local port 445 from

IP
> addresses outside the range. Does anyone have any experience on comparing
> how port reporter shows connections and the settings in the firewall?
>
> For example, say I have a network of computers with IP addresses of
> 131.180.240..xx and a subnet mask of 255.255.254.0. I only want traffic

to
> come from that network. I set the custom exception to
> 131.180.240.0/255.255.254.0. Is my custom exception list correct? Port
> reporter is showing connections to port 445 from an address like
> 131.180.200.20.


Don't know. Is the Device forcing "Classful Addressing"? If so, and if I'm
not mistaken, 131.x.x.x is a Class B,...therefore 131.180.200.x and
131.180.240.x would be in the same subnet (255.255.0.0) according to the
Class. I don't know,..it is just a shot in the dark.

Another thing to think about is that the Log may be showing "all" attempts
(allowed or denied) which would be the normal expected way for it to be
done. You can block them but you can never stop them from attempting,...it
just ain't gonna happen.

--
Phillip Windell [MCP, MVP, CCNA]
www.wandtv.com
-----------------------------------------------------
Understanding the ISA 2004 Access Rule Processing
http://www.isaserver.org/articles/IS...cessRules.html

Microsoft Internet Security & Acceleration Server: Guidance
http://www.microsoft.com/isaserver/t...dance/2004.asp
http://www.microsoft.com/isaserver/t...dance/2000.asp

Microsoft Internet Security & Acceleration Server: Partners
http://www.microsoft.com/isaserver/partners/default.asp
-----------------------------------------------------



 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Firewall port needed Clayton Windows Networking 2 06-27-2006 10:08 PM
LINUX/shorewall firewall to firewall VPN question sundog@mountaindogs.net Linux Networking 3 03-14-2006 04:04 PM
Firewall / Port Forwarding Carter B. Bennett Linux Networking 1 11-27-2004 06:43 AM
Firewall Seeing Port 137, 138 UDP Traffic Google Mike Linux Networking 6 08-04-2004 10:03 PM
Stupid Question: Port Triggering vs. Port Forwarding Bryce Wireless Internet 3 09-09-2003 05:45 AM



1 2 3 4 5 6 7 8 9 10 11