In news:71B49853-94E3-41A7-A429-(E-Mail Removed),
Yann <(E-Mail Removed)> typed:
> Hello,
>
> First of all, I apologize to post this on this subsection of the
> forum but when I see the idiots who are in the Learning > MCSE Exam
> subsection, I'm pretty sure that I won't get any answer from there.
> (read the answers for the post called "Need MCSE Book" and you'll
> understand what I am talking about). Anyway...
>
> Can anyone please explain me the answer from the MSPress Book 70-291
> (page 9-84 for those of you who have this book) for the following
> question:
>
> "You have deployed a Windows Server 2003 computer running the Routing
> And Remote Access Service router to function as a simple firewall.
> How many packet filters do you need to create to support remote
> access to a VPN server through L2TP/IPSec? Assume that you want to
> provide the strictest security standards."
>
> Answer:
>
> Twelve
>
>
> Hmmmm... why 12 ?
>
> Thanks a lot for your answers
I would assume 4, which is what I would open up, because L2TP/IPSec uses the
following ports:
L2TP = TCP 1701
ESP = Protocol ID 50
AH = Protocol ID 51
SA = UDP 500
If you were to allow PPTP, then you would need these ports in additon:
GRE TCP 1723
Protocol ID 47
Of course we also would assume to have opened appropriate ports if there are
services being published, such as OWA, web services, DNS services, etc
I would like to hear the explanation for the twelve ports to see what I am
missing.
Ace
Innovative IT Concepts, Inc (IITCI)
Willow Grove, PA
This posting is provided "AS-IS" with no warranties or guarantees and
confers no rights.
Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSE+I, MCT, MVP
Microsoft MVP - Directory Services
Microsoft Certified Trainer
Infinite Diversities in Infinite Combinations
Having difficulty reading or finding responses to your post?
Instead of the website you're using, try using OEx (Outlook Express
or any other newsreader), and configure a news account, pointing to
news.microsoft.com. Anonymous access. It's free - no username or password
required nor do you need a Newsgroup Usenet account with your ISP. It
connects directly to the Microsoft Public Newsgroups. OEx allows you
o easily find, track threads, cross-post, sort by date, poster's name,
watched threads or subject. It's easy:
How to Configure OEx for Internet News
http://support.microsoft.com/?id=171164
"Quitting smoking is easy. I've done it a thousand times." - Mark TwainAce