Great Circle Associates Firewalls
(July 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Access to TCP Port 113
From: paul @ hawksbill . sprintmrn . com (Paul Ferguson)
Date: Wed, 12 Jul 1995 19:20:33 -0500 (EST)
To: G . Fengstad @ CdnAir . CA (Grant M. Fengstad)
Cc: firewalls @ greatcircle . com
In-reply-to: <Pine . A32 . 3 . 91 . 950712143000 . 27800B-100000 @ valiant . te . CdnAir . CA> from "Grant M. Fengstad" at Jul 12, 95 02:31:56 pm

> 
> I have noticed several denied packets from outside systems attempting to 
> poke at tcp port 113 on one of my DMZ systems.
> 
> TCP 113 is defined as the authentication port.  I can not seem to get a 
> clear explanation as to what service(s) on the client side would be 
> attempting to do this.  This port is not enabled on our host sides.
> 
> I'd appreciate any input and/or clarification.
> 
> 


tcp/113 is ident protocol (RFC-1413).
 
Filtering it may cause problems with some applications, to include
some TELNET implementations. Some applications still send a tcp/113
auth request as back-channel response to incoming connections.

Blocking _shouldn't_ wreak too much havoc, but you may notice that
establishing connections to outside services may seem to hang during
the connection process while the tcp/113 request times out.

My vote: Block it.


- paul


_______________________________________________________________________________
Paul Ferguson                         
US Sprint                                          tel: 703.689.6828
Managed Network Engineering                   internet: paul @
 hawk .
 sprintmrn .
 com
Reston, Virginia  USA                             http://www.sprintmrn.com 


Follow-Ups:
References:
Indexed By Date Previous: icepick
From: staatsvr @ ss2 . sews . wpafb . af . mil (VERN R. STAATS)
Next: nfswatch on SLIP/PPP lines
From: sjs @ sunthing . sjsinc . com (Stefan Jon Silverman)
Indexed By Thread Previous: Access to TCP Port 113
From: "Grant M. Fengstad" <G . Fengstad @ CdnAir . CA>
Next: Re: Access to TCP Port 113
From: Julian Assange <proff @ suburbia . apana . org . au>

Google
 
Search Internet Search www.greatcircle.com