Great Circle Associates Firewalls
(July 1994)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: UDP thru Firewall (Was: Prospero protocol and filters)
From: Rens Troost <rens @ imsi . com>
Date: Thu, 21 Jul 1994 16:25:25 -0400
To: Ken Jones <kenj @ group1 . com>
Cc: plarkin @ iphase . com, firewalls @ greatcircle . com
In-reply-to: Your message of "Thu, 21 Jul 1994 10:24:38 PDT." <9407211024 . aa08274 @ duke . group1 . com>
Reply-to: rens @ imsi . com

>>>>> "Ken" == Ken Jones <kenj @
 group1 .
 com> writes:

  Ken> My understanding is letting in udp packets on ports >1023 is
  Ken> generally safe, as the only listeners on those ports are
  Ken> clients such as archie waiting for a specific response.

  Ken> You also (if you are running unix) need to check /etc/services
  Ken> to verify there isn't anything configured to listen to ports
  Ken> above 1023 by default.

Beware! This is not accurate. Most interesting RPC servers bind to UDP
ports in the dynamic range. Here's a sample listing from a sun
(rpcinfo):

    100011    1   udp   1042  rquotad
    100001    2   udp   1043  rstatd
    100001    3   udp   1043  rstatd
    100001    4   udp   1043  rstatd
    100002    1   udp   1044  rusersd
    100002    2   udp   1044  rusersd
    100012    1   udp   1045  sprayd
    100008    1   udp   1046  walld
    100003    2   udp   2049  nfs
    100021    1   udp   1035  nlockmgr

All kinds of good stuff in the dynamic range. It is safest to block
all UDP, letting in only a few select ports (DNS, NTP).

-Rens


References:
Indexed By Date Previous: Re: UDP thru Firewall (Was: Prospero protocol and filters)
From: Aydin Edguer <edguer @ MorningStar . Com>
Next: RE: Security of Appletalk and Dial back modems
From: "Spaulding" <spaulding @ maillink . calgene . com>
Indexed By Thread Previous: Re: UDP thru Firewall (Was: Prospero protocol and filters)
From: Aydin Edguer <edguer @ MorningStar . Com>
Next: Re: UDP thru Firewall (Was: Prospero protocol and filters)
From: Brent Chapman <brent @ mycroft . GreatCircle . COM>

Google
 
Search Internet Search www.greatcircle.com